A vulnerability was identified in Pagure's rendering engine for reStructuredText (RST) files. By default, the docutils library allows the inclusion of local files using the .. include:: directive. Because Pagure does not restrict or jail this directive during the rendering process, an authenticated user can exploit this to read arbitrary internal files from the server hosting Pagure.