CVE-2026-60004: Gitea Code Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-25. EPSS: 24% chance of exploitation in the next 30 days.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Affected products

  • Gitea Gitea: from 1.17.0, before 1.27.1 (fixed in 1.27.1)

Published 2026-08-26. Last modified 2026-08-27.