THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Gitea flaw, tracked as CVE-2026-60004, to its Known Exploited Vulnerabilities catalog. This vulnerability allows an attacker with write access to execute arbitrary shell commands as the Gitea service user, affecting Gitea versions prior to 1.27.1. The flaw can be exploited without existing credentials due to Gitea's default open registration, leading to potential attacks such as deploying cryptocurrency mining payloads.
CISA mandates federal agencies to remedy this vulnerability by August 28, 2026, while private organizations are advised to review and address listed vulnerabilities.