A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote code execution. The issue affects Gitea versions from 1.22.1 through 1.27.0 and is fixed in version 1.27.1. The vulnerability is documented as GHSA-6v53-hr58-556r and carries a Critical severity rating. It has a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that exploitation can occur remotely, requires no account, no user interaction, and can compromise confidentiality, integrity, and availability. The flaw exists in Gitea’s repository markup-rendering feature. An attacker can send a crafted request to the...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!