CVE-2026-59774 is a critical vulnerability in the Gitea product that enables unauthenticated remote code execution and arbitrary file read, posing significant business impact. The flaw type is a command injection issue, which occurs when user-controlled input is not properly sanitized before being executed by the system, allowing an attacker to inject malicious commands and execute them on the server-side. This vulnerability can be exploited via the environment template management API, where an attacker can send a specially crafted request that injects malicious code into the API endpoint. Once injected, the attacker can read arbitrary files on the system, further escalating the attack. The flaw has a high CVSS score and allows attackers to gain unauthorized access to sensitive data and potentially disrupt critical operations, making it essential for organizations to address this vulnerability promptly.
We recommend you upgrade to Gitea 1.27.1[/subscribe_to_unlock_form]
CVE-2026-59774 is a critical vulnerability in the Gitea product that enables unauthenticated remote code execution and arbitrary file read, posing significant business impact. The flaw type is a command injection issue, which occurs when user-controlled input is not properly sanitized before being executed by the system, allowing an attacker to inject malicious commands and execute them on the server-side. This vulnerability can be exploited via the environment template management API, where an attacker can send a specially crafted request that injects malicious code into the API endpoint. Once injected, the attacker can read arbitrary files on the system, further escalating the attack. The flaw has a high CVSS score and allows attackers to gain unauthorized access to sensitive data and potentially disrupt critical operations, making it essential for organizations to address this vulnerability promptly.
We recommend you upgrade to Gitea 1.27.1[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]