← back

CVE-2026-60004

CRITICAL · 9.8 KEV EPSS 86.8%
hype ACTIVE HACK · 92 hack

KEV confirmation + multiple threat intel reports of active exploitation + patched version available.

What: Code injection / remote code execution in Gitea (self-hosted Git service) affecting authenticated users via the diffpatch API; CVSS 9.8 reported.

Why it matters: KEV-listed as of 2026-08-25 with confirmed in-the-wild exploitation. Multiple sources cite active attacks against Gitea instances. Patch available (v1.27.1+). Self-hosted deployments with open registration particularly at risk, often positioned near build and OT networks.

Where it's seen: CISA KEV announcement driving coordinated social signal across security media. Posts cite threat intelligence reports, urgent patching guidance, and technical details (signup form → shell access via diffpatch). No public PoC linked in posts, but exploitation confirmed by threat feeds.

RISK: CRITICAL — KEV-listed, active in-the-wild exploitation, high CVSS (9.8), RCE on git infrastructure.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 8/26/2026, 2:13:08 PM

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses