DIRAS TAKE
Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, and public exploit code exists, so prioritize updating to 1.27.1 or applying vendor mitigations immediately.
What is CVE-2026-60004?
Attackers can run arbitrary commands as the Gitea service by exploiting a code injection flaw in Gitea's diffpatch API (CVE-2026-60004). Affected releases are Gitea 1.17 up to but not including 1.27.1; the issue is fixed in 1.27.1. The vulnerability requires the ability to send a malicious patch (repository write access) that plants an executable Git hook and triggers shell execution via the diffpatch endpoint.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Gitea Gitea are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.17 – before 1.27.1 | 1.27.1 |
Is CVE-2026-60004 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-25, and U.S. federal agencies were required to act by 2026-08-28; public exploit code is also available.
How to fix CVE-2026-60004
- Upgrade Gitea to 1.27.1, which contains the fix.
- If you cannot upgrade immediately, restrict repository write access and block public access to Gitea instances.
- Apply any vendor-recommended mitigations and configuration changes from Gitea guidance.
- Monitor Gitea logs and system activity for signs of unauthorized hook creation or shell execution.
Frequently asked questions
Is CVE-2026-60004 being actively exploited?
Yes — CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on 2026-08-25, with remediation required by 2026-08-28 for federal agencies.
Which Gitea versions are affected by CVE-2026-60004?
Gitea versions 1.17 through before 1.27.1 are affected; the issue is fixed in 1.27.1.
Is there a patch for CVE-2026-60004?
Yes — Gitea 1.27.1 includes the fix for CVE-2026-60004.
Does CVE-2026-60004 require authentication?
Exploitation requires the ability to send a malicious patch with repository write access rather than being purely unauthenticated.
References
- nvd.nist.gov/vuln/detail/CVE-2026-60004
- cve.org/CVERecord?id=CVE-2026-60004
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004
- blog.gitea.com/release-of-1.27.1
- github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
- runzero.com/blog/gitea
- github.com/0xBlackash/CVE-2026-60004
- All Gitea CVEs on CVE Radar
- CVEs published in September 2026