


Perceptive Security
SOC/SIEM Consultancy

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Published:
26 August 2026 at 00:00:00
Alert date:
26 August 2026 at 23:00:59
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities, Supply Chain & Dependencies
CVE-2026-60004 is a critical remote code execution vulnerability affecting Gitea versions prior to 1.27.1. The vulnerability exists in the diffpatch API, which can be exploited to install malicious Git hooks, ultimately allowing an attacker to execute arbitrary code on the server. A patch was released in Gitea version 1.27.1. A public proof-of-concept exploit has been published on GitHub. The vulnerability has been assigned a high criticality rating and is documented in a GitHub Security Advisory under GHSA-rcr6-4jqh-j84m. Organizations running self-hosted Gitea instances are urged to upgrade immediately to mitigate the risk of remote compromise.
Technical details
Mitigation steps:
Affected products:
Gitea (versions before 1.27.1)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-60004
https://blog.gitea.com/release-of-1.27.1/
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
https://www.runzero.com/blog/gitea/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
