Gitea Patches Critical Unauthenticated File-Read Flaw CVE-2026-59774 Found by an Autonomous AI Pentesting System
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
Editor's Note ·
- Correction:
- The article states the finding was 'triaged by Guido Leo, who also goes by the handle NightRang3r.' Neither The Hacker News nor Gitea's GitHub Security Advisory (GHSA-6v53-hr58-556r) supports this. The advisory's credits separately list Guido Leo (gleo-xbow) as the triaging analyst and NightRang3r as the independent reporter; The Hacker News identifies the NightRang3r handle as belonging to Shai Rod, not Guido Leo. Guido Leo and NightRang3r/Shai Rod are two distinct individuals.
Overview
Gitea, the self-hosted Git service used by developers to run their own code-hosting instances, has patched a critical, unauthenticated file-read vulnerability that carried a CVSS score of 9.8, according to The Hacker News and the project’s own GitHub Security Advisory. Tracked as CVE-2026-59774, the flaw allowed attackers with no login credentials to pull arbitrary files off a vulnerable Gitea server, and it was found by XBOW Security’s autonomous offensive-security system, according to The Hacker News.
What We Know
The vulnerability lives in Gitea’s markup rendering feature, specifically the POST /{owner}/{repo}/markup endpoint, which accepts unauthenticated requests against public repositories, according to The Hacker News. Gitea initializes the third-party go-org library used to render Org-mode markup without overriding its default ReadFile callback, and the Org-mode #+INCLUDE directive accepts absolute file paths — meaning an attacker could submit crafted markup, select file-inclusion mode, and have the server hand back the contents of any file its service account could read, according to The Hacker News and the GitHub Security Advisory.
The advisory assigns the bug a CVSS 3.1 score of 9.8, with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a network-exploitable flaw that needs no authentication and no user interaction, according to the GitHub Security Advisory. It affects Gitea versions 1.22.1 through 1.27.0 and is fixed in 1.27.1, according to The Hacker News and the GitHub Security Advisory.
Gitea’s own release announcement shows the fix shipped inside version 1.27.1 on July 27, 2026, credited to pull requests #38642 and #38645, according to Gitea’s blog. The formal GitHub Security Advisory carrying the CVE number and CVSS score followed on August 2, 2026, according to The Hacker News — meaning server operators who upgraded promptly for the release were already protected before the advisory spelled out the severity.
The flaw’s discovery is credited to XBOW Security, which The Hacker News describes as an autonomous offensive-security system, with the finding triaged by Guido Leo, who also goes by the handle NightRang3r; a researcher going by Shai Rod, using the same NightRang3r handle, reported the same issue independently, according to The Hacker News. The GitHub advisory’s credits section lists the finders as XBOW security and Guido Leo, with NightRang3r listed as an independent reporter, according to the GitHub Security Advisory. XBOW describes its own product as an autonomous system that explores applications and APIs the way an attacker would, chaining vulnerabilities into working attacks and proving exploitability before a finding reaches a customer’s security team, according to XBOW’s website.
Beyond the raw file-read capability, both The Hacker News and the GitHub advisory describe a theoretical path to full remote code execution: an attacker could use the file-read bug to extract an INTERNAL_TOKEN value from Gitea’s app.ini configuration file, then use that token to inject a malicious Git hook through the service’s internal logger, triggering code execution when the hook fires during an anonymous repository clone, according to The Hacker News and the GitHub Security Advisory. No independent proof-of-concept demonstrating that full escalation chain had been published as of The Hacker News’s report, and as of that report no exploitation in the wild had been observed and the CVE had not been added to CISA’s Known Exploited Vulnerabilities catalog, according to The Hacker News.
CVE-2026-59774 was not the only fix in the 1.27.1 release. Gitea’s blog post for the release also credits the same version with patching CVE-2026-60004, a remote-code-execution flaw in the project’s diffpatch API that lets an attacker install a malicious Git hook, reported by NightRang3r and patched by contributor wxiaoguang, according to Gitea’s blog. That RCE flaw was previously reported by The Machine Herald days before this file-read bug’s advisory went public — meaning Gitea shipped fixes for two separate critical-severity vulnerabilities in the same point release.
What We Don’t Know
Neither The Hacker News nor the GitHub advisory discloses how many Gitea instances remained on vulnerable versions at the time of disclosure, or whether any organization’s server was compromised through this specific bug before the patch shipped. The full remote-code-execution escalation chain described in the advisory remains theoretical in public reporting, with no published proof-of-concept confirming it works end to end, according to The Hacker News.
Analysis
The episode illustrates a shift already visible across the vulnerability-research field: an automated, AI-driven testing system credited as the primary finder of a critical bug in widely deployed developer infrastructure, alongside a human researcher who reached the same finding independently. Gitea is exactly the kind of software such systems are built to probe — internet-facing, open to public repositories by default, and central enough to a development workflow that a single unauthenticated file-read bug can cascade into full server compromise if left unpatched.