
Critical Gitea Vulnerability Exposes Configuration Files, Tokens and Server Secrets
A critical vulnerability in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files on vulnerable servers and potentially escalate to remote code execution (RCE). The flaw, disclosed in GHSA-6v53-hr58-556r, affects Gitea versions 1.22.1 through 1.27.0 and has been fixed in version 1.27.1. The vulnerability carries a CVSS v3.1 score of Critical, with […]
The post Critical Gitea Vulnerability Exposes Configuration Files, Tokens and Server Secrets appeared first on Cyber Security News.