Gitea has patched a critical remote code execution flaw, CVE-2026-60004, affecting versions 1.17 through 1.27.0, after researchers showed that attacker-controlled patch content sent to the POST /api/v1/repos/{owner}/{repo}/diffpatch endpoint could be turned into a malicious Git hook and executed as the Gitea service account. The bug carries a CVSS 9.8 rating and stems from patch application inside a shared bare temporary clone, where Git's three-way fallback can activate the planted hook; exploitation also depends on Git 2.32 or later. Gitea fixed the issue in version 1.27.1 and said its cloud instances would be upgraded automatically.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
MITRE published and updated the CVE-2026-60004 record, classifying the Gitea diffpatch API Git-hook issue as CWE-94 code injection with a CVSS v3.1 score of 9.8. The record states that Gitea versions 1.17 through before 1.27.1 are affected and that 1.27.1 fixes the issue.
Public proof-of-concept exploit code exists for the Gitea vulnerability, increasing the risk of exploitation on exposed instances. Gitea's advisory said it had not observed in-the-wild exploitation as of July 29, 2026.
Gitea patched a critical remote code execution vulnerability, CVE-2026-60004, affecting versions 1.17 through 1.27.0/ before 1.27.1. The flaw allows a repository writer to turn crafted patch content into a malicious Git hook and execute shell commands as the Gitea service account.
A ProjectDiscovery Nuclei template for detecting CVE-2026-60004 in Gitea was developed and then corrected after false positives were found on patched versions. The update consolidated matcher conditions with && and added flow logic so the sign-up page check runs only after a vulnerable version is identified.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcerunzero.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.