A critical file read vulnerability in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read arbitrary files accessible to the service account via crafted Org-mode markup. The flaw is fixed in Gitea 1.27.1.
A critical file read vulnerability in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read arbitrary files accessible to the service account via crafted Org-mode markup. The flaw is fixed in Gitea 1.27.1.