CVE-2026-60004
CRITICAL · 9.8 KEV EPSS 86.8%KEV confirmation + multiple threat intel reports of active exploitation + patched version available.
What: Code injection / remote code execution in Gitea (self-hosted Git service) affecting authenticated users via the diffpatch API; CVSS 9.8 reported.
Why it matters: KEV-listed as of 2026-08-25 with confirmed in-the-wild exploitation. Multiple sources cite active attacks against Gitea instances. Patch available (v1.27.1+). Self-hosted deployments with open registration particularly at risk, often positioned near build and OT networks.
Where it's seen: CISA KEV announcement driving coordinated social signal across security media. Posts cite threat intelligence reports, urgent patching guidance, and technical details (signup form → shell access via diffpatch). No public PoC linked in posts, but exploitation confirmed by threat feeds.
RISK: CRITICAL — KEV-listed, active in-the-wild exploitation, high CVSS (9.8), RCE on git infrastructure.
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High