Description
Forgejo versions 7.0 through 15.0.5 and 16.0.0 through 16.0.1 are vulnerable to an arbitrary file read via the markup rendering API endpoint. The go-org library's default ReadFile callback (ioutil.ReadFile) is not overridden, allowing the #+INCLUDE directive to read arbitrary files accessible to the service user.
Valid credentials are required to access the API markup endpoint. Extracting sensitive files such as app.ini can expose INTERNAL_TOKEN and other secrets, potentially leading to remote code execution.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/gather/forgejo/orgmode_fileread_cve_2026_59774msf undefined(orgmode_fileread_cve_2026_59774) > show actions ...actions...msf undefined(orgmode_fileread_cve_2026_59774) > set ACTION < action-name >msf undefined(orgmode_fileread_cve_2026_59774) > show options ...show and set options...msf undefined(orgmode_fileread_cve_2026_59774) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub