Gitea has patched a critical remote code execution flaw, CVE-2026-60004, affecting versions 1.17 through 1.27.0, after researchers showed that attacker-controlled patch content sent to the POST /api/v1/repos/{owner}/{repo}/diffpatch endpoint could be turned into a malicious Git hook and executed as the Gitea service account. The bug carries a CVSS 9.8 rating and stems from patch application inside a shared bare temporary clone, where Git's three-way fallback can activate the planted hook; exploitation also depends on Git 2.32 or later. Gitea fixed the issue in version 1.27.1 and said its cloud instances would be upgraded automatically.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public proof-of-concept exploit code exists for the Gitea vulnerability, increasing the risk of exploitation on exposed instances. Gitea's advisory said it had not observed in-the-wild exploitation as of July 29, 2026.
Gitea patched a critical remote code execution vulnerability, CVE-2026-60004, affecting versions 1.17 through 1.27.0/ before 1.27.1. The flaw allows a repository writer to turn crafted patch content into a malicious Git hook and execute shell commands as the Gitea service account.
A ProjectDiscovery Nuclei template for detecting CVE-2026-60004 in Gitea was developed and then corrected after false positives were found on patched versions. The update consolidated matcher conditions with && and added flow logic so the sign-up page check runs only after a vulnerable version is identified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcerunzero.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.