Remote Code Execution Vulnerability in Gitea by Gitea
CVE-2026-60004

9.8CRITICAL

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
26 August 2026

Badges

👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-60004?

CVE-2026-60004 is a significant vulnerability found in Gitea, an open-source self-hosted Git service known for providing a simple and easy-to-use interface for managing Git repositories. The vulnerability allows for remote code execution via the diffpatch API, leveraging Git hook installation. This means that an attacker could potentially execute arbitrary code on the server, leading to a complete compromise of the affected system. Given that Gitea is used by various organizations for source code management and collaboration, this vulnerability can severely impact the confidentiality, integrity, and availability of sensitive code and data.

Potential Impact of CVE-2026-60004

  1. Unauthorized System Access: The remote code execution capability of this vulnerability allows attackers to gain unauthorized access to the underlying server, which can lead to complete system takeover and manipulation of files and settings.

  2. Data Breach Risk: Exploitation of this vulnerability may result in the exposure of sensitive code and data housed within the Gitea instances, potentially leading to significant data breaches that could compromise proprietary or confidential information.

  3. Widespread Malware Dissemination: With the ability to execute arbitrary code, attackers can deploy malware or ransomware on the affected systems, which might also facilitate lateral movement within an organization’s network, thereby exacerbating the overall security threat.

Affected Version(s)

Gitea 1.17 < 1.27.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

11 hours ago

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.

16 hours ago

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.

1 month ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • 📰

    First article discovered by The Hacker News

  • Vulnerability Reserved

.