What happened
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Affected versions
Gitea: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · EQSTLab/CVE-2026-60004Gitea diffpatch RCERCEPython★ 1⑂ 0Code indexedUpdated 26 Aug 2026EQSTLab2026-07-30CandidateCVE-Intel · fevar54/cve-2026-60004CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.ExploitPython★ 0⑂ 0Code indexedUpdated 25 Aug 2026Tags: cve-pocsfevar542026-08-25CandidateCVE-Intel · imbas007/CVE-2026-60004-POCCVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)RCEPython★ 15⑂ 6Code indexedUpdated 21 Aug 2026Tags: 1day, cve, cve-2026-60004, exploit, gitea, nuclei, nuclei-template, pocimbas0072026-08-03CandidateCVE-Intel · gagaltotal/CVE-2026-60004-poc-giteaCVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injectionRCEGo★ 2⑂ 0Code indexedUpdated 11 Aug 2026Tags: auth, gitea, gitea-api, go, golang, golang-cli, rce, rce-exploitgagaltotal2026-08-08CandidateCVE-Intel · Sachinart/CVE-2026-60004-gitea-0dayCVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCERCEPython★ 0⑂ 0Code indexedUpdated 4 Aug 2026Sachinart2026-08-04CandidateCVE-Intel · HackSpeak/CVE-2026-60004Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service accountRCEPython★ 1⑂ 0Code indexedUpdated 4 Aug 2026HackSpeak2026-08-04CandidateCVE-Intel · shinthink/CVE-2026-60004CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1RCEPython★ 0⑂ 0Code indexedUpdated 3 Aug 2026Tags: code-injection, cve, cve-2026-60004, exploit, forgejo, git, gitea, hookshinthink2026-08-03CandidateCVE-Intel · HORKimhab/CVE-2026-60004CVE-2026-60004ExploitPython★ 4⑂ 0Code indexedUpdated 31 Jul 2026HORKimhab2026-07-29CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.