A critical vulnerability (CVE-2026-59774) in Gitea (version 1.27.1 and earlier) allows unauthenticated attackers to read arbitrary server files and potentially execute remote code due to a flaw in the markup preview functionality. This issue affects self-hosted Git servers and can be exploited without user interaction. Users are advised to upgrade to version 1.27.1 immediately as the vulnerability is rated with a CVSS score of 9.8 and poses significant risk to exposed instances with public repositories.
Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
CyberSIXT Evidence Panel
Article by CyberSIXT