Skip to content

Known CVE

Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read

Gitea versions 1.22.1 through 1.27.0 initialize the go-org markup renderer without replacing its default ReadFile callback. An unauthenticated attacker can submit Org-mode markup containing an #+INCLUDE directive with an absolute path to the repository markup endpoint of any public repository, causing the server to read and render arbitrary files accessible to the Gitea service user.

CVE-2026-59774

Critical2026CVSS 9.8CWE-22

cve2026 · gitea · lfi · traversal · markup

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website