An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.
The file-read flaw is tracked as CVE-2026-59774, rated Critical...
📰 IT Security Nachrichten
⚡ iShareStuff Intelligence
📰 VERIFIED NEWS INTELLIGENCE ID: #3677497
📰 Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
⏱️ vor 3d 17h (05.08.2026 um 13:04 Uhr) 📖 1 Min. Lesezeit 📂 📰 IT Security Nachrichten 📡 Feed 🔗 Quelle: thehackernews.com
Schrift:
Verwandte Videos & News · KI-empfohlen via Levenshtein-Match
🎯 47% Match
📆 17.05.2023 um 15:00 Uhr
▶ Abspielen
🎯 39% Match
📆 12.01.2025 um 19:00 Uhr
▶ Abspielen
🎯 38% Match
📆 29.03.2025 um 18:00 Uhr
▶ Abspielen
🎯 37% Match
📆 16.07.2019 um 08:40 Uhr
▶ Abspielen
🎯 36% Match
📆 18.02.2025 um 15:00 Uhr
▶ Abspielen
🎯 36% Match
📆 11.02.2025 um 19:00 Uhr
▶ Abspielen
🎯 31% Match
📆 03.04.2025 um 22:00 Uhr
▶ Abspielen
🎯 31% Match
📆 11.04.2025 um 20:00 Uhr
▶ Abspielen
← Horizontal scrollen für mehr Empfehlungen → · Klick auf ein Video zum Abspielen im Hauptplayer