Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read
CVE-2026-59774
Verified
Description
Gitea versions 1.22.1 through 1.27.0 initialize the go-org markup renderer without replacing its default ReadFile callback. An unauthenticated attacker can submit Org-mode markup containing an #+INCLUDE directive with an absolute path to the repository markup endpoint of any public repository, causing the server to read and render arbitrary files accessible to the Gitea service user.
Severity
Critical
CVSS Score
9.8
Affected Product
gitea
Published Date
August 10, 2026
Template Author
ashish-cybersec
CVE-2026-59774.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-59774
CWE ID:
cwe-22
Remediation Steps
Update to Gitea version 1.27.1 or later.