Gitea 1.27.1 is released security patch
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-59774, CVE-2026-60004, Summary: This release addresses the following security vulnerabilities. Please upgrade as soon as possible. CVE-2026-59774: Unauthenticated arbitrary file read via the Org-mode #+INCLUDE directive. Fixed by #38642 / #38645. Thanks to @xbow-security and, independently, @NightRang3r for reporting the issue, and to @wxiaoguang and @TheFox0x7 for the patch. CVE-2026…
KEV ✓ CVSS 9.8 CVE-2026-59774 CVE-2026-60004 Gitea FI