{"id":"CVE-2026-60004","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","summary":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-94"],"vendor":"Gitea","product":"Gitea","affected":["Gitea >= 1.17 < 1.27.1"],"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-08-26T20:21:46.783249Z"},"exploited":true,"exploitAvailable":true,"published":"2026-08-26","updated":"2026-09-08","sourceUpdated":"2026-09-08T18:03:21.873Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-60004","references":[{"url":"https://blog.gitea.com/release-of-1.27.1/"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m"},{"url":"https://www.runzero.com/blog/gitea/"},{"url":"https://github.com/0xBlackash/CVE-2026-60004"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60004"},{"url":"https://github.com/go-gitea/gitea/pull/38637"},{"url":"https://github.com/go-gitea/gitea/pull/38638"},{"url":"https://github.com/go-gitea/gitea/commit/470d34b1de87d901bd9135564d5ee18c0d339e82"},{"url":"https://github.com/go-gitea/gitea/commit/d7bc52beeadff4be5f5690de4d5de42abd10affe"},{"url":"https://blog.gitea.com/release-of-1.27.1"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.1"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004"},{"url":"https://www.runzero.com/blog/gitea"},{"url":"https://github.com/advisories/GHSA-rcr6-4jqh-j84m"}],"tags":["cve.org","in-the-wild","exploit-available","ghsa","go","kev"],"aliases":["GHSA-rcr6-4jqh-j84m"],"ecosystem":"go","patched":["gitea.dev 1.27.1"],"epss":0.86777,"epssPercentile":0.9974,"kev":true,"kevDateAdded":"2026-08-25","kevDueDate":"2026-08-28","kevRansomware":false,"exploits":{"github":10,"githubRepos":["https://github.com/imbas007/CVE-2026-60004-POC","https://github.com/HORKimhab/CVE-2026-60004","https://github.com/0xBlackash/CVE-2026-60004"],"nuclei":["CVE-2026-60004"],"checkedAt":"2026-09-21T15:29:51.323Z"},"zeroDay":true,"ingestedAt":"2026-09-08T18:07:34.881Z","slug":"CVE-2026-60004","body":"## Overview\n\nGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.\n\n## Affected\n\n- `Gitea >= 1.17 < 1.27.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-60004)\n\nAffected packages:\n\n- `gitea.dev >= 1.17.0, < 1.27.1`\n\nPatched in:\n\n- `gitea.dev 1.27.1`\n\nSource: https://github.com/advisories/GHSA-rcr6-4jqh-j84m","depth":"hadal","depthScore":96,"depthScoreParts":{"impact":53.9,"likelihood":17.4,"exploitation":25,"ransomware":0},"changes":[]}