securityonline.info 7/29/2026, 10:11:43 AM · external

CVE-2026-60004: Gitea RCE lets attackers run code via Git hook

CVE-2026-60004: Gitea RCE lets attackers run code via Git hook
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

GITEA has a critical Remote Code Execution (RCE) vulnerability tracked as CVE-2026-60004, with a CVSS score of 9.8. Users with repository write access can execute shell commands as the Gitea service account. The vulnerability is located in the diffpatch endpoint, allowing attackers to exploit it and run commands via a malicious Git hook. Affected versions are from 1.17 to below 1.27.1, requiring Git 2.32 or newer with enabled diffpatch. To mitigate, users should update to Gitea 1.27.1 or disable open registration.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline