Crypto Ticker:
sysadmin from Cyber Security News

Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

Abinaya
Tuesday at 11:27
8 Views
0 Comments
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote code execution. The issue affects Gitea versions from 1.22.1 through 1.27.0 and is fixed in version 1.27.1. The vulnerability is documented as GHSA-6v53-hr58-556r and carries a Critical severity rating. It has a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that exploitation can occur remotely, requires no account, no user interaction, and can compromise confidentiality, integrity, and availability. The flaw exists in Gitea’s repository markup-rendering feature. An attacker can send a crafted request to the...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!