Gitea v1.27.1 and Forgejo v15.0.6, v16.0.2 fixed an arbitrary file read via
the Org-mode #+INCLUDE directive.

Gitea announcement mentioned CVE-2026-59774, but it's not yet published.

Announcements:
https://blog.gitea.com/release-of-1.27.1/#security
https://codeberg.org/forgejo/security-announcements/issues/57

Relevant Pull Requests:
https://github.com/go-gitea/gitea/pull/38642
https://codeberg.org/forgejo/forgejo/pulls/13682

Best Regards,
Tianyu Chen

Reply via email to