CVE-2026-60004: Gitea Code Injection Vulnerability
Published Aug 25, 2026
·Updated
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Affected Software
1 affected component
Gitea Gitea
Event History
Aug 25, 2026
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs write access to a repository in the affected Gitea instance. They can use that access to submit a malicious patch to the diffpatch API endpoint.
2
What level of access could successful exploitation provide?
Successful exploitation can plant an executable Git hook and run shell commands as the Gitea service account. The resulting access is limited by the privileges assigned to that service account.
3
Is there evidence of active exploitation?
Yes. The vulnerability is flagged as exploited and was listed in the Known Exploited Vulnerabilities catalog on 2026-08-25.