Critical Gitea RCE Vulnerability Allows Execution of Shell Commands via Git Hooks
A critical remote code execution vulnerability (CVE-2026-60004) in Gitea allows attackers with repository write access to execute shell commands via malicious Git hooks. The flaw, patched in version 1.27.1, was exploitable via the /api/v1/repos/{owner}/{repo}/diffpatch endpoint without prior credentials due to default open registration.
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.
Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
*** END OF TRANSMISSION ***