Critical Gitea file-read flaw patched in 1.27.1
π An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1β1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
