/Vulnerability Library

Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read

CVE-2026-59774
Verified

Description

Gitea versions 1.22.1 through 1.27.0 initialize the go-org markup renderer without replacing its default ReadFile callback. An unauthenticated attacker can submit Org-mode markup containing an #+INCLUDE directive with an absolute path to the repository markup endpoint of any public repository, causing the server to read and render arbitrary files accessible to the Gitea service user.

Severity

Critical

CVSS Score

9.8

Affected Product

gitea

Published Date

August 10, 2026

Template Author

ashish-cybersec

CVE-2026-59774.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-59774
CWE ID:
cwe-22

References

https://github.com/go-gitea/gitea/security/advisories/GHSA-6v53-hr58-556rhttps://nvd.nist.gov/vuln/detail/CVE-2026-59774

Remediation Steps

Update to Gitea version 1.27.1 or later.