CVE-2026-60004: Gitea Code Injection Vulnerability
Summary
Gitea has a code injection vulnerability in its diffpatch API endpoint, allowing authenticated users to execute shell commands as the Gitea service account by planting a malicious Git hook. Affected users are advised to apply vendor-provided mitigations and follow CISA's guidance on prioritizing security updates.
IFF Assessment
This vulnerability allows for arbitrary code execution on the Gitea service account, posing a significant risk to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 28, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Gitea allows for command execution, which could be leveraged for further compromise or to deploy ransomware. Defenders should prioritize patching or mitigating this vulnerability on any Gitea instances they manage, especially those exposed to the internet.