Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-60004: Gitea can execute attacker commands via malicious patch
CVE-2026-60004 · published 8 days ago · actively exploited
Summary
If someone can write to a repository in Gitea, they could upload a specially crafted change that places a script on the server and runs commands with the same rights as the Gitea service. This could let an attacker control the server or steal data. Apply the latest Gitea update or restrict write access to trusted users to fix the problem.
What to do
- Update gitea gitea to version 1.27.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea |
< 1.27.1 >= 1.17.0, < 1.27.1 |
Original advisory text
Gitea Code Injection Vulnerability
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Severity
9.8
Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 87%
Type
CWE-94Code Injection
Timeline
Published26 Aug 2026
Updated2 Sep 2026
First seen25 Aug 2026
Monitor software like this
Free during beta