CRITICAL
CVE-2026-60004
CVSS
9.8
KEV
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Summary dbcve.org
Gitea versions before 1.27.1 contain a critical vulnerability in the diffpatch API that allows authenticated users to install malicious Git hooks. Since Git hooks execute arbitrary code during repository operations, this enables complete remote code execution on the Gitea server.
Mitigation
Upgrade Gitea to version 1.27.1 or later. If immediate upgrade is not feasible, restrict access to the diffpatch API endpoint through network-level controls or authentication requirements.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
86.78%
Probability of exploitation in next 30 days
99.7th percentile
References
https://blog.gitea.com/release-of-1.27.1/
Release Notes
https://github.com/0xBlackash/CVE-2026-60004
Exploit, Mitigation, Third Party Advisory
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
Exploit, Vendor Advisory
https://www.runzero.com/blog/gitea/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.