← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 00:00via CISA KEV

CVE-2026-60004 - Gitea Code Injection Vulnerability

Brief

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Read more on CISA KEV