Critical Gitea flaw let unauthenticated attackers read files from vulnerable self-hosted servers

A critical bug in Gitea could let anyone on the internet read files from vulnerable self-hosted code servers without logging in. The flaw is described as an unauthenticated arbitrary file-read issue triggered through Org-mode markup rendering; the article indicates it affects Gitea and exposes server-side files, creating a path to leak secrets or configuration data from internet-facing instances.
Why it matters: Organizations and developers running self-hosted Gitea could have sensitive files exposed to strangers, including data that may help attackers move deeper into systems. This is urgent for internet-exposed instances: admins should identify affected versions, restrict exposure where possible, and apply vendor fixes or mitigations immediately.

Sources

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
info@thehackernews.com (The Hacker News) 2026.08.05 100% relevant
This article appears to establish a distinct new Gitea vulnerability story centered on unauthenticated file disclosure via Org-mode markup, which is different from the already tracked Gitea private-container-image exposure flaw.
← Back to all stories