Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Published 26 Aug 2026Updated 26 Aug 2026146 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.