CVE-2026-60004: Gitea Code Injection Vulnerability

Summary

Gitea has a code injection vulnerability in its diffpatch API endpoint, allowing authenticated users to execute shell commands as the Gitea service account by planting a malicious Git hook. Affected users are advised to apply vendor-provided mitigations and follow CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution on the Gitea service account, posing a significant risk to defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 28, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Gitea allows for command execution, which could be leveraged for further compromise or to deploy ransomware. Defenders should prioritize patching or mitigating this vulnerability on any Gitea instances they manage, especially those exposed to the internet.

Read Full Story →