CRITICALVulnerability
Global

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

·Source: The Hacker News

Updated:

Executive Summary

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Analysis

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Indicators of Compromise (1)

CVE (1)
CVE-2026-60004
Source Attribution

Originally published by The Hacker News on Jul 29, 2026.

Related Threats