Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News by The Hacker News
August 5, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalAug 05, 2026Vulnerability / DevOps

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.

The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004, a separate remote code execution bug covered in a prior THN report.

Gitea said Cloud instances would be upgraded automatically during the release maintenance window. Self-hosted administrators should move to 1.27.1 immediately.

The file-read bug is not direct one-request remote code execution. Gitea says it can become command execution if an attacker reads app.ini, extracts INTERNAL_TOKEN, injects a Git hook through the internal logger, and triggers that hook during an anonymous clone.

That chain is described in Gitea’s advisory; The Hacker News found no independently published exploit demonstrating it.

Upgrading is necessary but may not be sufficient after suspected exposure. If logs show the markup endpoint was reached on an affected build, treat credentials readable by the Gitea service account as exposed and rotate the internal token, OAuth material, JWT signing material, and database credentials before considering the instance clean.

No badge required

The file-read path runs through Gitea’s markup rendering endpoint, POST /{owner}/{repo}/markup. The route allows optional sign-in, resolves the repository, and checks reader access. An anonymous request clears that check against any public repository with its code unit enabled. That precondition limits the unauthenticated exposure: an instance with no public repositories has no anonymous attack path through this endpoint.

The break is in Gitea’s Org-mode renderer. Gitea 1.27.0 initialized go-org with org.New() and did not replace the library’s default ReadFile callback. In go-org 1.9.1, that callback is ioutil.ReadFile. Org-mode’s #+INCLUDE directive accepts absolute paths and passes them to the callback. An attacker submits Org-mode markup, selects Mode: file, and receives files the service account can read.

The fix landed in PR #38642 and was backported in PR #38645. Gitea now overrides ReadFile so an Org-mode include path is returned as plain rendered content instead of being resolved from the server filesystem. The patch added a regression test for include-path rendering.

CVE-2026-59774 was found by XBOW Security, an autonomous offensive security system, and triaged by Guido Leo. Shai Rod, known online as NightRang3r, independently reported the same issue.

What administrators should check

Gitea did not publish formal detection guidance in the advisory. Review anonymous POST requests to /{owner}/{repo}/markup, especially requests selecting Org-mode rendering or submitting absolute filesystem paths. If the advisory’s escalation path was attempted, check repository hook directories for unexpected executable files.

Gitea’s advisory reports no exploitation in the wild, and as of August 5, 2026, CVE-2026-59774 had not appeared on CISA’s Known Exploited Vulnerabilities catalog. The file-read primitive was publicly previewed before its formal advisory, according to a prior THN report. The token-to-hook command-execution chain remains single-sourced to Gitea’s advisory.

The flaw follows a dense stretch of Gitea security work. In June, Gitea patched a critical reverse-proxy authentication bypass in Docker images, CVE-2026-20896, that threat actors were observed probing 13 days after disclosure. In May, a container-registry access-control flaw, CVE-2026-27771, was estimated to affect more than 30,000 deployments across over 30 countries.



Source link

The Hacker News

The Hacker News

Next Post
KYNDRYL REPORTS FIRST QUARTER FISCAL 2027 RESULTS

KYNDRYL REPORTS FIRST QUARTER FISCAL 2027 RESULTS

Recommended.

Manual Processes Are Putting National Security at Risk

Manual Processes Are Putting National Security at Risk

February 25, 2026
[MWC 2026] GlobalData publiceert een whitepaper over de evolutie van spraakdiensten in het AI-tijdperk

[MWC 2026] GlobalData publiceert een whitepaper over de evolutie van spraakdiensten in het AI-tijdperk

March 13, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio