Skip to content
THREATWIRE

Threats

The Gitea diffpatch bug is listed by CISA

CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.

Critical

Published 5 Oct 2026

What happened

Gitea 1.27.1 was released on 27 July 2026. The project blog lists CVE-2026-60004 as remote code execution through the diffpatch API by installing a Git hook, fixed in that version, and thanks NightRang3r for the report. GitHub advisory GHSA-rcr6-4jqh-j84m says the endpoint can be abused to install and execute a Git hook from repository-controlled content. The affected range is 1.17.0 through versions before 1.27.1. NVD scores it 9.8 and records CWE-94.

CISA added the CVE to the Known Exploited Vulnerabilities catalog on 25 August 2026. Federal civilian agencies had a due date of 28 August 2026. Known ransomware use is unknown.

Who is affected

Gitea instances from 1.17 through 1.27.0 are in the version range. Gitea Cloud is called out in the 1.27.1 release as upgraded by the project during its maintenance window. Self-hosted instances stay on the operator.

The CISA entry is more specific than the NVD score. It says the attacker needs repository write access, can send a malicious patch to the diffpatch API, and can then run shell commands as the Gitea service account. An account that cannot write to a repository is outside that sentence even if the version is old.

What is confirmed

The fix version, the 27 July 2026 release date, the write-access condition, and the KEV listing are all in those sources. The status is Active Exploitation because CISA listed it. NVD links a public repository, 0xBlackash/CVE-2026-60004, created on 30 July 2026. Another public repository, HORKimhab/CVE-2026-60004, was created on 29 July 2026. Both are after the fix.

What is not confirmed

NVD’s CVSS vector says no privileges are required. CISA says write access is required. ThreatWire shows 9.8 as the only published number and does not delete the privilege from the catalog entry. The record is not a 0-day: 1.27.1 existed before the 25 August KEV date.

A Cloud Security Alliance research note uses the name Red Heron for later exploitation of this CVE. That name is not in the CISA entry and not in the Gitea 1.27.1 announcement. It stays out of the CVE record.

What to do

Upgrade internet-facing Gitea to 1.27.1 or later. The KEV action is the vendor fix plus the forensic triage CISA attaches to BOD 26-04. Repository write access is the condition to review, including instances that hand out accounts that can push. The patch contents used to plant the hook are not reprinted here.

Sources: the Gitea 1.27.1 blog post, advisory GHSA-rcr6-4jqh-j84m, the CISA KEV entry for CVE-2026-60004, and NVD.


Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/threats/gitea-diffpatch-bug-is-listed-by-cisa