CVE-2026-60004
CRITICALGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Published: 8/26/2026Modified: 8/27/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (5)
https://blog.gitea.com/release-of-1.27.1/Release Noteshttps://github.com/0xBlackash/CVE-2026-60004ExploitMitigationhttps://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84mExploitVendor Advisoryhttps://www.runzero.com/blog/gitea/Third Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004US Government Resource