Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-60004: Gitea diffpatch Git Hook Installation Remote Code Execution Exploit PoC

Summary

A PoC for CVE-2026-60004, a critical RCE in Gitea (<1.27.1). It abuses the diffpatch endpoint to plant a malicious Git hook, giving command execution as the Gitea service account.

Why it matters

When self-registration is enabled, any unauthenticated attacker can create an account and immediately achieve host-level remote code execution on self-hosted Gitea instances.
CVE
CVE-2026-60004
Vendor
Gitea
Product
Gitea
Affected versions
>= 1.17, < 1.27.1
CVSS
9.8
Published
Collected

original ↗