πŸ”΄ CVE-2026-60004

CVE-2026-60004 is a critical (CVSS 9.8) remote code execution vulnerability in Gitea before 1.27.1, exploitable via the diffpatch API through Git hook installation. Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the Gitea service account, resulting in full server compromise. It is listed in CISA KEV with confirmed active exploitation and public PoC availability.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-26

Added to CISA KEV: 2026-08-25 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-14)

Summary

CVE-2026-60004 is a critical remote code execution (RCE) vulnerability affecting Gitea versions prior to 1.27.1. The flaw exists within the application's `diffpatch` API, which can be manipulated to facilitate the unauthorized installation of Git hooks. Because this vulnerability allows an attacker to execute arbitrary shell commands with the privileges of the underlying Gitea service account, it poses a severe risk of full system compromise, including data theft, unauthorized modification of repositories, and potential lateral movement within the hosting infrastructure [1][3].

Exploitation

  • Active Exploitation: The vulnerability has been identified as a Known Exploited Vulnerability (KEV) by CISA, confirming that it is being actively exploited in the wild [2].
  • Threat Actors: While specific advanced persistent threat (APT) groups or ransomware campaigns have not been publicly attributed to this CVE, its status in the KEV catalog indicates widespread interest from malicious actors [2].
  • PoC/Exploit Availability: Proof-of-concept code and educational materials regarding this vulnerability are publicly available on platforms such as GitHub [6].
  • Attack Prerequisites: Exploitation requires the attacker to have repository write access [2][4].

Affected Products & Patches

  • Affected Versions: Gitea versions prior to 1.27.1 [3][5].
  • Patch Availability: The vulnerability was addressed in Gitea version 1.27.1; users are advised to upgrade to this version or newer immediately to remediate the risk [3].
  • Mitigations/Workarounds: No specific workarounds are recommended beyond upgrading, as the patch is the primary and most effective method for securing affected systems.

Impact

  • Access/Capability: Successful exploitation grants the attacker the ability to execute arbitrary shell commands on the server running Gitea, effectively resulting in full control over the host system [1][5].
  • Business Risk: For internet-facing deployments, this risk is critical. It can lead to the exfiltration of sensitive source code, intellectual property theft, service disruption, and the potential for the compromised server to be used as a beachhead for further attacks against the organization's internal network [1][4].

Sources

  1. CVE-2026-60004 - Vulnerability Details - OpenCVE

    The vulnerability can be leveraged by sending specially crafted diffpatch requests that cause the server to execute arbitrary shell commands with the privileges of the Gitea process. It enables full compromise of the host system, leading to data theft, modification, or service disruption.

  2. Known Exploited Vulnerabilities Catalog

    CVE-2026-60004 Gitea Code Injection Vulnerability: Gitea contains a code injection vulnerability that allows an attacker with repository write ...

  3. NVD-CVE-2026-60004 - NIST

    CVE-2026-60004 Detail Description Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Base ...

  4. CVE-2026-60004 - Exploits & Severity - Feedly

    CVEs. CVE-2026-60004. TrendingProof of Concept ExploitFeedly KEV.A critical vulnerability in Gitea, with a CVSS score of 9.8, allows attackers with repository write access to execute arbitrary shell commands as the Gitea service account, posing significant risks due to many deployments using default…

  5. CVE-2026-60004 - Critical Vulnerability - TheHackerWire

    CVE-2026-60004 is a Critical severity vulnerability (CVSS 9.8). Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. ... CVE-2026-60004 is a Critical severity security vulnerability. Gitea before 1.27.1 allows remote code execution via the diffpatch A…