Skip to content
THREATWIRE

CVE

CriticalActive ExploitationKEV

CVE-2026-60004

Gitea diffpatch Git hook code execution

Gitea before 1.27.1 lets a user with repository write access run commands as the Gitea service account through the diffpatch API. CISA listed it on 25 August 2026. The fix shipped on 27 July 2026. NVD scores it 9.8.

CVSS
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Class
RCE
Status
Active Exploitation
KEV
Listed in CISA KEV
0-day
No
Vendor
Gitea
Products
Gitea
Affected
1.17.0 through 1.27.0.
Fixed
1.27.1, released 27 July 2026.
Published
27 Jul 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-60004 is code injection in Gitea’s diffpatch API. The project shipped the fix in 1.27.1 on 27 July 2026 and credits NightRang3r for the report. GitHub advisory GHSA-rcr6-4jqh-j84m says the endpoint can be abused to install and execute a Git hook from repository-controlled content. The affected range is 1.17.0 up to, but not including, 1.27.1. NVD scores it 9.8 and records CWE-94.

CISA added it to the Known Exploited Vulnerabilities catalog on 25 August 2026, with a federal due date of 28 August 2026. The catalog entry says the attacker needs repository write access, then can plant an executable Git hook and run shell commands as the Gitea service account. NVD’s vector says no privileges are required. This record keeps 9.8 as the published number and follows CISA on the write-access condition. Known ransomware use is unknown.

The fix existed before the KEV date, so this is not marked a 0-day. NVD links a public repository, 0xBlackash/CVE-2026-60004. The hook-installation steps are not reprinted.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-60004