Remote Code Execution Vulnerability in Gitea by Gitea
CVE-2026-60004
Key Information:
Badges
What is CVE-2026-60004?
CVE-2026-60004 is a significant vulnerability found in Gitea, an open-source self-hosted Git service known for providing a simple and easy-to-use interface for managing Git repositories. The vulnerability allows for remote code execution via the diffpatch API, leveraging Git hook installation. This means that an attacker could potentially execute arbitrary code on the server, leading to a complete compromise of the affected system. Given that Gitea is used by various organizations for source code management and collaboration, this vulnerability can severely impact the confidentiality, integrity, and availability of sensitive code and data.
Potential Impact of CVE-2026-60004
-
Unauthorized System Access: The remote code execution capability of this vulnerability allows attackers to gain unauthorized access to the underlying server, which can lead to complete system takeover and manipulation of files and settings.
-
Data Breach Risk: Exploitation of this vulnerability may result in the exposure of sensitive code and data housed within the Gitea instances, potentially leading to significant data breaches that could compromise proprietary or confidential information.
-
Widespread Malware Dissemination: With the ability to execute arbitrary code, attackers can deploy malware or ransomware on the affected systems, which might also facilitate lateral movement within an organization’s network, thereby exacerbating the overall security threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gitea 1.17 < 1.27.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
11 hours ago
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
16 hours ago
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.
1 month ago
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
- 📰
First article discovered by The Hacker News
Vulnerability Reserved
