• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-60004: authenticated code injection in Gitea Gitea

Attackers can run arbitrary commands as the Gitea service by exploiting a code injection flaw in Gitea's diffpatch API (CVE-2026-60004). Affected releases are Gitea 1.17 up to but not including 1.27.1; the issue is fixed in 1.27.1. The vulnerability requires the ability to send a malicious patch (repository write access) that plants an executable Git hook and triggers shell execution via the diffpatch endpoint.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.23988
CWE
CWE-94
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, and public exploit code exists, so prioritize updating to 1.27.1 or applying vendor mitigations immediately.

What is CVE-2026-60004?

Attackers can run arbitrary commands as the Gitea service by exploiting a code injection flaw in Gitea's diffpatch API (CVE-2026-60004). Affected releases are Gitea 1.17 up to but not including 1.27.1; the issue is fixed in 1.27.1. The vulnerability requires the ability to send a malicious patch (repository write access) that plants an executable Git hook and triggers shell execution via the diffpatch endpoint.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Gitea Gitea are affected?

BRANCHAFFECTEDFIXED
1.x1.17 – before 1.27.11.27.1

Is CVE-2026-60004 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-25, and U.S. federal agencies were required to act by 2026-08-28; public exploit code is also available.

How to fix CVE-2026-60004

  1. Upgrade Gitea to 1.27.1, which contains the fix.
  2. If you cannot upgrade immediately, restrict repository write access and block public access to Gitea instances.
  3. Apply any vendor-recommended mitigations and configuration changes from Gitea guidance.
  4. Monitor Gitea logs and system activity for signs of unauthorized hook creation or shell execution.

Frequently asked questions

Is CVE-2026-60004 being actively exploited?

Yes — CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on 2026-08-25, with remediation required by 2026-08-28 for federal agencies.

Which Gitea versions are affected by CVE-2026-60004?

Gitea versions 1.17 through before 1.27.1 are affected; the issue is fixed in 1.27.1.

Is there a patch for CVE-2026-60004?

Yes — Gitea 1.27.1 includes the fix for CVE-2026-60004.

Does CVE-2026-60004 require authentication?

Exploitation requires the ability to send a malicious patch with repository write access rather than being purely unauthenticated.

References