CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads
ID: d4dd5a65-c9e7-5d0f-bed8-00a6a0b26708
STIX ID: report--d4dd5a65-c9e7-5d0f-bed8-00a6a0b26708
Feed Name: SOC Prime Blog
A critical RCE in Gitea (CVE-2026-60004, CVSS 9.8) allows authenticated users with repository write access to craft patches that become executable Git hooks and run arbitrary commands as the Gitea service account; the flaw affects Gitea 1.17 through 1.27.0 and was fixed in 1.27.1. CISA added the vulnerability to its KEV catalog after public disclosure and at least one real-world compromise that deployed a miner-like dropper; a public PoC and detection signatures exist, increasing exploitation risk. Immediate actions recommended are upgrading to 1.27.1+, disabling public registration where unnecessary, auditing for suspicious diffpatch activity and unexpected processes, and rotating exposed credentials if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
