CVE-2026-60004 – Gitea

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A vulnerable diffpatch workflow can turn repository operations into remote code execution.”

Gitea before 1.27.1 contains a Critical remote code execution vulnerability in the diffpatch API. CVE-2026-60004 allows an attacker to achieve code execution through Git hook installation. The CVSS score is 9.8, which is Critical severity.

The issue is fixed in Gitea 1.27.1.

Key Details

Affected Product
Gitea Gitea
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.