GITEA has a critical Remote Code Execution (RCE) vulnerability tracked as CVE-2026-60004, with a CVSS score of 9.8. Users with repository write access can execute shell commands as the Gitea service account. The vulnerability is located in the diffpatch endpoint, allowing attackers to exploit it and run commands via a malicious Git hook. Affected versions are from 1.17 to below 1.27.1, requiring Git 2.32 or newer with enabled diffpatch. To mitigate, users should update to Gitea 1.27.1 or disable open registration.
CVE-2026-60004: Gitea RCE lets attackers run code via Git hook
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CVE-2026-60004: Gitea RCE lets attackers run code via Git hook
securityonline.info
-
Gitea Git Hook Flaw Allows Remote Code Execution on Servers
thehackernews.com