🔴 Critical  |  Source: The Hacker News


A critical vulnerability in Gitea versions 1.22.1 through 1.27.0 allows any unauthenticated attacker to read arbitrary files accessible to the Gitea service account, simply by crafting malicious Org-mode markup in a public repository. No credentials or write access are required, making exploitation trivially easy. The flaw is patched in Gitea 1.27.1 and carries a CVSS score of 9.8.

Security Architect’s Take: Upgrade all Gitea instances to version 1.27.1 immediately; if patching is not possible right now, restrict public repository access and place Gitea behind network-level controls to limit unauthenticated exposure. Additionally, audit the permissions of the Gitea service account to minimise the blast radius of any file-read exploitation.

Original advisory: Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup