CRITICAL

CVE-2026-60004

Gitea Gitea 2026-08-26 CVSS v3.1
CVSS
9.8
KEV

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Summary dbcve.org

Gitea versions before 1.27.1 contain a critical vulnerability in the diffpatch API that allows authenticated users to install malicious Git hooks. Since Git hooks execute arbitrary code during repository operations, this enables complete remote code execution on the Gitea server.

Mitigation

Upgrade Gitea to version 1.27.1 or later. If immediate upgrade is not feasible, restrict access to the diffpatch API endpoint through network-level controls or authentication requirements.

Proof of Concept

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

86.78%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE