CVE-2026-60004: Gitea Code Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-25. EPSS: 24% chance of exploitation in the next 30 days.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Affected products
- Gitea Gitea: from 1.17.0, before 1.27.1 (fixed in 1.27.1)
Published 2026-08-26. Last modified 2026-08-27.