SECURITY·중요도 9·2026. 08. 05.·The Hacker News

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

── KO ──────────────────

Gitea의 심각한 취약점으로 인해 인증되지 않은 공격자가 서버 파일을 읽을 수 있음.

Gitea의 1.22.1부터 1.27.0 버전에서 인증되지 않은 공격자가 서비스 계정이 접근할 수 있는 모든 파일을 읽을 수 있는 심각한 취약점이 발견되었습니다. 로그인이 필요 없으며, 공개 레포지토리와 조작된 Org-mode 마크업만 있으면 됩니다. 이 취약점은 CVE-2026-59774로 추적되며, CVSS 점수는 9.8로 평가되었습니다. Gitea 1.27.1에서 이 문제가 수정되었습니다.


── EN ──────────────────

A critical flaw in Gitea allows unauthenticated attackers to read server files.

A critical vulnerability found in Gitea versions 1.22.1 to 1.27.0 allows unauthenticated attackers to read any files accessible to the service account. No login is required; just a public repository and crafted Org-mode markup are sufficient. This flaw is tracked as CVE-2026-59774 and has a CVSS score of 9.8. It was fixed in Gitea version 1.27.1.

원문 보기 →목록으로