CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3888

As cited

Copy frozen at (site build).

vulnerabilities

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read arbitrary files accessible to the Gitea service account by exploiting a flaw in Org-mode markup processing. The vulnerability affects Gitea versions 1.22.1 through 1.27.0 and requires only access to a public repository. The issue is resolved in Gitea 1.27.1.

Why it matters: Organizations running self-hosted Gitea instances in the affected versions face immediate confidentiality risk and should upgrade to 1.27.1 or later to prevent unauthorized file disclosure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read arbitrary files accessible to the Gitea service account by exploiting a flaw in Org-mode markup processing. The vulnerability affects Gitea versions 1.22.1 through 1.27.0 and requires only access to a public repository. The issue is resolved in Gitea 1.27.1.

Why it matters: Organizations running self-hosted Gitea instances in the affected versions face immediate confidentiality risk and should upgrade to 1.27.1 or later to prevent unauthorized file disclosure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary