GITEA has a critical Remote Code Execution (RCE) vulnerability tracked as CVE-2026-60004, with a CVSS score of 9.8. Users with repository write access can execute shell commands as the Gitea service account. The vulnerability is located in the diffpatch endpoint, allowing attackers to exploit it and run commands via a malicious Git hook. Affected versions are from 1.17 to below 1.27.1, requiring Git 2.32 or newer with enabled diffpatch. To mitigate, users should update to Gitea 1.27.1 or disable open registration.
CVE-2026-60004: Gitea RCE lets attackers run code via Git hook
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Weekly CVE Report: 11 Exploited Flaws Added to KEV
securityonline.info
-
CISA's KEV Catalog Adds Gitea Flaw, Urges Prompt Patching
cisa.gov
-
CISA Adds Critical Gitea Flaw CVE-2026-60004 to Exploit List
securityaffairs.com
-
CISA Warns of Exploited Gitea Flaw CVE-2026-60004 Patch by Aug 28
securityweek.com
-
CISA Flags Gitea Code Injection Flaw in KEV Catalogue
cisa.gov
-
CVE-2026-60004: Gitea RCE lets attackers run code via Git hook
securityonline.info