code.gitea.io/gitea is vulnerable to Path Traversal
98
Critical Risk
The Org-mode markup renderer used by POST /{owner}/{repo}/markup initializes go-org with its default ReadFile callback, so a #+INCLUDE directive can read arbitrary absolute paths as the Gitea service user. An unauthenticated attacker can hit that route on a public repository, extract secrets such as INTERNAL_TOKEN from app.ini, and chain them into Git hook injection for remote code execution. The fix constrains Org-mode file inclusion so markup rendering cannot read arbitrary server paths.
You are affected if you are using a version that falls within the vulnerable range and at least one repository is publicly readable with a code unit that the markup route accepts.
code.gitea.io/gitea is vulnerable to Path Traversal in versions 1.22.1 - 1.27.0.
Upgrade the gitea.dev and/or the code.gitea.io/gitea library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.