Gitea diffpatch endpoint RCE (CVE-2026-60004)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-60004 is a critical remote code execution flaw in Gitea that lets a user with repository write access run shell commands as the Gitea service account. The bug affects Gitea 1.17 through 1.27.0 and is fixed in 1.27.1. Public proof-of-concept code is available, raising the risk of rapid exploitation on exposed installations.
Related Happenings
Vim and GNU Emacs file-open RCE flaws remote code execution flaw
Vulnerability
H score28
First: 01.04.2026 00:45
Last: 01.04.2026 00:45
Sources 1
About this happening:
Vim and GNU Emacs have file-open remote code execution flaws that can run attacker code as soon as a crafted file is opened. The Vim issue affects 9.2.0271 and e...
Vim and GNU Emacs file-open RCE flaws remote code execution flaw
VulnerabilityAbout this happening: Vim and GNU Emacs have file-open remote code execution flaws that can run attacker code as soon as a crafted file is opened. The Vim issue affects 9.2.0271 and e...
Timeline
-
29.07.2026 10:47 1 articles · 2h ago
Gitea backports the diffpatch hook fix
Mitigation Patch UpdateGitea changed the temporary clone used by POST /api/v1/repos/{owner}/{repo}/diffpatch from bare to non-bare, closing the hook-placement behavior that let an executable file land in hooks/post-index-change and become active while Git updated the index.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
-
29.07.2026 10:47 1 articles · 2h ago
Gitea ships version 1.27.1 with the CVE-2026-60004 fix
Mitigation Patch UpdateGitea released version 1.27.1 with the fix for CVE-2026-60004, and Gitea Cloud instances were slated for automatic upgrade on the same day.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
-
28.07.2026 03:00 2 articles · 1d ago
Gitea issues advisory for CVE-2026-60004 and publishes PoC code
Initial DisclosureGitea's July 28 security advisory for CVE-2026-60004 says the flaw had not been exploited in the wild and includes public proof-of-concept code. Gitea also credits security researcher Shai Rod, who goes by NightRang3r, as the reporter.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47