Gitea Unauthenticated File Read + RCE Chain: Every Self-Hosted Instance Before 1.27.1 Is at Risk — CVE-2026-59774
Gitea 1.22.1 through 1.27.0 allows an unauthenticated attacker to read any file the server process can access via Org-mode #+INCLUDE path traversal in the…