logo

Gitea vulnerability CVE-2026-60004: find impacted assets

ID: 573ed3d2-0ce7-55dd-8b44-586b2b43267d

STIX ID: report--573ed3d2-0ce7-55dd-8b44-586b2b43267d

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Matthew Kienow

...
...

A critical remote code execution vulnerability (CVE-2026-60004) in Gitea's diffpatch feature allows remote or authenticated attackers with repository write access to inject Git hooks and execute arbitrary commands as the Gitea process; affected versions are 1.17 through 1.27.0 (CVSS 9.8). Administrators are advised to upgrade to Gitea 1.27.1 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.