CVE Details

CVE-2026-60004 Gitea Code Injection Vulnerability
Published: 2026-08-25 Product: Gitea Gitea Due Date: 2026-08-28

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • killvxk/gitweekly • ⭐ 110 • 2025-07-22 • Conf: 95.0%
  • 收集各种有趣的github项目
  • zulloper/cve-poc • ⭐ 17 • 2025-06-08 • Conf: 90.0%
  • CVE POC repo 자동 수집기
  • imbas007/CVE-2026-60004-POC • ⭐ 15 • 2026-08-03 • Conf: 96.0%
  • CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
  • HORKimhab/CVE-2026-60004 • ⭐ 4 • 2026-07-29 • Conf: 95.0%
  • CVE-2026-60004

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

No EPSS data.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

No MITRE data.