The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENABLE_GIT_HOOKS line in the config file). NOTE: The vendor has indicated this is not a vulnerability and states "This is a functionality of the software that is limited to a very limited subset of accounts. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your server. We provide very clear warnings to users around this functionality and what it provides.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small PoC/operational exploit for CVE-2020-14144 (Gitea authenticated RCE via Git Hooks) with 3 files: (1) README.md describing the vulnerability, requirements, and automated usage; (2) a manual exploitation guide (named "Manual" in the provided listing; README references MANUAL.md) walking through creating a repo, editing the post-receive hook, starting a netcat listener, and triggering via git push; and (3) exploit.py, a Python3 script that automates the full chain. Core exploit flow in exploit.py: - Establishes an HTTP session to the target Gitea base URL and extracts CSRF tokens/UID from HTML. - Authenticates to /user/login with provided credentials. - Deletes any existing repo with the chosen name, then creates a fresh repository via /repo/create (including uid for older versions). - Writes a malicious post-receive git hook (default bash reverse shell for Linux or PowerShell reverse shell for Windows; optional custom payload file). - Logs out, then triggers execution by performing git operations (clone/commit/push) against the created repository, causing the server-side post-receive hook to run. Capabilities: - Authenticated remote code execution as the Gitea service user by injecting arbitrary commands into a repository hook. - Reverse shell payloads (Linux /dev/tcp bash; Windows PowerShell TCP client) and support for custom hook script payloads. - Basic operational conveniences: CSRF/UID scraping, repo lifecycle management (delete/create), and automated trigger via local git. No evidence of unrelated destructive/fake behavior; it is not merely a detector. The exploit is operational but not a full framework module (payload customization is limited to OS choice or supplying a payload file).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2020-14144, an authenticated remote code execution vulnerability in Gitea (prior to 1.13.0) when git hooks are enabled. The exploit works by authenticating to the Gitea web interface, creating a temporary repository, setting a malicious post-receive git hook, and then triggering it by committing a file. The module supports multiple platforms (Linux, Unix, Windows) and can deliver various payloads, including reverse shells and Meterpreter sessions. The attack requires valid credentials for a user with git hook creation permissions. The module is weaponized, allowing for easy payload customization and automated exploitation. The main endpoints targeted are the Gitea web interface and specific repository management URLs. The code is structured as a standard Metasploit exploit module, with options for target URI, username, and password, and includes cleanup routines to remove artifacts after exploitation.
This repository contains a Python exploit script (CVE-2020-14144-GiTea-git-hooks-rce.py) targeting CVE-2020-14144, an authenticated remote code execution vulnerability in GiTea versions 1.1.0 through 1.12.5. The exploit requires valid credentials for a user with 'May create git hooks' rights. The script automates the process of logging in, creating a repository, setting a malicious post-receive git hook (which can be a reverse shell or a custom shell script), and triggering the hook by pushing a commit. The exploit leverages several HTTP endpoints of the GiTea web interface to perform these actions. The README provides detailed usage instructions, requirements, and demonstration screenshots. The repository is structured with a single main exploit script, a README, and a funding configuration file. The exploit is operational, providing a working reverse shell payload by default, and allows for custom payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.