THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installation

[GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installation

highgithub_advisoriesPublished 2026-09-08

GHSA-rcr6-4jqh-j84m Severity: critical CVE: CVE-2026-60004

Gitea: Remote Code Execution via diffpatch Git Hook Installation

### Summary

Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content.

An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rcr6-4jqh-j84m