Local File Inclusion in Gitea by go-gitea via file:// URI
CVE-2026-58420
Currently unrated
What is CVE-2026-58420?
A local file inclusion vulnerability exists in Gitea due to improper handling of file:// URIs during migration restore operations. This flaw could allow an attacker to access sensitive files on the server, potentially leading to unauthorized data exposure.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
