A critical Gitea vulnerability lets unauthenticated attackers read files accessible to the service account through crafted Org-mode markup. CVE-2026-59774 affects versions 1.22.1 through 1.27.0 and is fixed in Gitea 1.27.1. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
