Remote Code Execution Vulnerability in Gitea by Gitea
CVE-2026-60004
Key Information:
Badges
What is CVE-2026-60004?
CVE-2026-60004 is a significant vulnerability found in Gitea, an open-source self-hosted Git service known for providing a simple and easy-to-use interface for managing Git repositories. The vulnerability allows for remote code execution via the diffpatch API, leveraging Git hook installation. This means that an attacker could potentially execute arbitrary code on the server, leading to a complete compromise of the affected system. Given that Gitea is used by various organizations for source code management and collaboration, this vulnerability can severely impact the confidentiality, integrity, and availability of sensitive code and data.
Potential Impact of CVE-2026-60004
-
Unauthorized System Access: The remote code execution capability of this vulnerability allows attackers to gain unauthorized access to the underlying server, which can lead to complete system takeover and manipulation of files and settings.
-
Data Breach Risk: Exploitation of this vulnerability may result in the exposure of sensitive code and data housed within the Gitea instances, potentially leading to significant data breaches that could compromise proprietary or confidential information.
-
Widespread Malware Dissemination: With the ability to execute arbitrary code, attackers can deploy malware or ransomware on the affected systems, which might also facilitate lateral movement within an organization’s network, thereby exacerbating the overall security threat.
CISA has reported CVE-2026-60004
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-60004 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Gitea 1.17 < 1.27.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Red Heron exploited Gitea CVE-2026-60004 to steal repositories, collect credentials, persist, and move laterally across victim networks
1 week ago
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.
3 weeks ago
CISA Confirms Gitea CVE-2026-60004 Exploited: Cryptominer Hits 5,000 Exposed Dev Servers
Gitea CVE-2026-60004, a CVSS 9.8 code-injection flaw, is now on CISA’s Known Exploited Vulnerabilities list after attackers deployed cryptocurrency-mining malware on unpatched dev servers. Federal
4 weeks ago
References
EPSS Score
86% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
- 🦅
CISA Reported
- 📰
First article discovered by The Hacker News
Vulnerability Reserved
