Gitea v1.27.1 and Forgejo v15.0.6, v16.0.2 fixed an arbitrary file read via the Org-mode #+INCLUDE directive.
Gitea announcement mentioned CVE-2026-59774, but it's not yet published. Announcements: https://blog.gitea.com/release-of-1.27.1/#security https://codeberg.org/forgejo/security-announcements/issues/57 Relevant Pull Requests: https://github.com/go-gitea/gitea/pull/38642 https://codeberg.org/forgejo/forgejo/pulls/13682 Best Regards, Tianyu Chen
