CVE-2026-60004: Gitea diffpatch Git Hook Installation Remote Code Execution Exploit PoC
github.com | vulnerability | Critical | CVE-2026-60004 | #rce | #gitea | #red-team | #exploitation | #poc | #cve-2026-60004 | #git-hooks
Summary
A PoC for CVE-2026-60004, a critical RCE in Gitea (<1.27.1). It abuses the diffpatch endpoint to plant a malicious Git hook, giving command execution as the Gitea service account.
Why it matters
When self-registration is enabled, any unauthenticated attacker can create an account and immediately achieve host-level remote code execution on self-hosted Gitea instances.
- CVE
- CVE-2026-60004
- Vendor
- Gitea
- Product
- Gitea
- Affected versions
- >= 1.17, < 1.27.1
- CVSS
- 9.8
- Published
- Collected
Skip to content