Local File Inclusion in Gitea by go-gitea via file:// URI
CVE-2026-58420

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58420?

A local file inclusion vulnerability exists in Gitea due to improper handling of file:// URIs during migration restore operations. This flaw could allow an attacker to access sensitive files on the server, potentially leading to unauthorized data exposure.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

isa0-gh
ibrahmsql
.