CVE-2026-60004 is a critical (CVSS 9.8) remote code execution vulnerability in Gitea before 1.27.1, exploitable via the diffpatch API through Git hook installation. Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the Gitea service account, resulting in full server compromise. It is listed in CISA KEV with confirmed active exploitation and public PoC availability.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-26
Added to CISA KEV: 2026-08-25 0 DAY BETWEEN CVE AND KEV
CVE-2026-60004 is a critical remote code execution (RCE) vulnerability affecting Gitea versions prior to 1.27.1. The flaw exists within the application's `diffpatch` API, which can be manipulated to facilitate the unauthorized installation of Git hooks. Because this vulnerability allows an attacker to execute arbitrary shell commands with the privileges of the underlying Gitea service account, it poses a severe risk of full system compromise, including data theft, unauthorized modification of repositories, and potential lateral movement within the hosting infrastructure [1][3].
The vulnerability can be leveraged by sending specially crafted diffpatch requests that cause the server to execute arbitrary shell commands with the privileges of the Gitea process. It enables full compromise of the host system, leading to data theft, modification, or service disruption.
CVE-2026-60004 Gitea Code Injection Vulnerability: Gitea contains a code injection vulnerability that allows an attacker with repository write ...
CVE-2026-60004 Detail Description Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Base ...
CVEs. CVE-2026-60004. TrendingProof of Concept ExploitFeedly KEV.A critical vulnerability in Gitea, with a CVSS score of 9.8, allows attackers with repository write access to execute arbitrary shell commands as the Gitea service account, posing significant risks due to many deployments using defaultβ¦
CVE-2026-60004 is a Critical severity vulnerability (CVSS 9.8). Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. ... CVE-2026-60004 is a Critical severity security vulnerability. Gitea before 1.27.1 allows remote code execution via the diffpatch Aβ¦