HackerFeeds

CyberSecurity News

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News
· August 5, 2026

AI summary

A critical vulnerability in Gitea, a self-hosted Git platform, allows unauthenticated attackers to read server files. This can be done by creating a public repository and using specially crafted Org-mode markup, without needing login or write access. The issue affects Gitea versions 1.22.1 through 1.27.0. The flaw has been fixed in version 1.27.1. The vulnerability is tracked as CVE-2026-59774 and has a CVSS score of 9.8, indicating a high level of severity.

Read the full article at The Hacker Newsthehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.