CVE Details

CVE-2026-60004 Gitea Code Injection Vulnerability
Published: 2026-08-25 CVSS: 9.8 CRITICAL Product: Gitea Gitea Due Date: 2026-08-28

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • killvxk/gitweekly • ⭐ 110 • 2025-07-22 • Conf: 95.0%
  • 收集各种有趣的github项目
  • zulloper/cve-poc • ⭐ 17 • 2025-06-08 • Conf: 90.0%
  • CVE POC repo 자동 수집기
  • imbas007/CVE-2026-60004-POC • ⭐ 15 • 2026-08-03 • Conf: 96.0%
  • CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
  • HORKimhab/CVE-2026-60004 • ⭐ 4 • 2026-07-29 • Conf: 95.0%
  • CVE-2026-60004

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

No EPSS data.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > affected > 0 > product Gitea
containers > cna > affected > 0 > vendor Gitea
containers > cna > affected > 0 > versions > 0 > lessThan 1.27.1
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 1.17
containers > cna > affected > 0 > versions > 0 > versionType custom
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > scenarios > 0 > lang en
containers > cna > metrics > 0 > scenarios > 0 > value GENERAL
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-94
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-94 Improper Control of Generation of Code ('Code Injection')
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > providerMetadata > dateUpdated 2026-08-26T19:45:00.000Z
containers > cna > providerMetadata > orgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
containers > cna > providerMetadata > shortName mitre
containers > cna > references > 0 > url https://blog.gitea.com/release-of-1.27.1/
containers > cna > references > 1 > url https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
containers > cna > references > 2 > url https://www.runzero.com/blog/gitea/
containers > cna > references > 3 > url https://github.com/0xBlackash/CVE-2026-60004
containers > cna > x_generator > engine Record Generation 0.0.1
cveMetadata > assignerOrgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
cveMetadata > assignerShortName mitre
cveMetadata > datePublished 2026-08-26T19:45:00.000Z
cveMetadata > dateReserved 2026-07-08T09:19:08.764Z
cveMetadata > dateUpdated 2026-08-26T19:45:00.000Z
cveMetadata > cveId CVE-2026-60004
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.2