Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Published 26 Aug 2026Updated 26 Aug 2026146 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Affected versions

Gitea: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · EQSTLab/CVE-2026-60004Gitea diffpatch RCERCEPython★ 1⑂ 0Code indexedUpdated 26 Aug 2026EQSTLab2026-07-30CandidateCVE-Intel · fevar54/cve-2026-60004CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.ExploitPython★ 0⑂ 0Code indexedUpdated 25 Aug 2026Tags: cve-pocsfevar542026-08-25CandidateCVE-Intel · imbas007/CVE-2026-60004-POCCVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)RCEPython★ 15⑂ 6Code indexedUpdated 21 Aug 2026Tags: 1day, cve, cve-2026-60004, exploit, gitea, nuclei, nuclei-template, pocimbas0072026-08-03CandidateCVE-Intel · gagaltotal/CVE-2026-60004-poc-giteaCVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injectionRCEGo★ 2⑂ 0Code indexedUpdated 11 Aug 2026Tags: auth, gitea, gitea-api, go, golang, golang-cli, rce, rce-exploitgagaltotal2026-08-08CandidateCVE-Intel · Sachinart/CVE-2026-60004-gitea-0dayCVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCERCEPython★ 0⑂ 0Code indexedUpdated 4 Aug 2026Sachinart2026-08-04CandidateCVE-Intel · HackSpeak/CVE-2026-60004Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service accountRCEPython★ 1⑂ 0Code indexedUpdated 4 Aug 2026HackSpeak2026-08-04CandidateCVE-Intel · shinthink/CVE-2026-60004CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1RCEPython★ 0⑂ 0Code indexedUpdated 3 Aug 2026Tags: code-injection, cve, cve-2026-60004, exploit, forgejo, git, gitea, hookshinthink2026-08-03CandidateCVE-Intel · HORKimhab/CVE-2026-60004CVE-2026-60004ExploitPython★ 4⑂ 0Code indexedUpdated 31 Jul 2026HORKimhab2026-07-29Candidate