THREAT OPS › CVEs › CVE-2026-60004
CVE-2026-60004 — Gitea Code Injection Vulnerability
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Vulnerability details
- Affected productsGitea
- KEV remediation due2026-08-28
Related reporting
- August 2026 CVE Landscaperecordedfuture
- [GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installationgithub_advisories
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payloadthehackernews
- Gitea security advisory (AV26-845)cccs_ca
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-60004 — Gitea Gitea: Gitea Code Injection Vulnerabilitycisa_kev
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commandsthehackernews