THREAT OPS › Threat News › [GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installation
[GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installation
GHSA-rcr6-4jqh-j84m Severity: critical CVE: CVE-2026-60004
Gitea: Remote Code Execution via diffpatch Git Hook Installation
### Summary
Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content.
An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-60004cve
- https://gitea.exampleurl
- poc@example.invalidemail
Original source: https://github.com/advisories/GHSA-rcr6-4jqh-j84m