Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3634 articles · 197874 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-60004KEVEXPLOITEDPATCHED
gitea · gitea

CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Affected Products

VendorProductVersions
giteagitea1.17

References

  • https://blog.gitea.com/release-of-1.27.1/
  • https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
  • https://www.runzero.com/blog/gitea/
  • https://github.com/0xBlackash/CVE-2026-60004

Related News (4 articles)

Tier C
VulDB2h ago
CVE-2026-60004 | Gitea up to 1.27.0 Diffpatch API os command injection
→ No new info (linked only)
Tier E
Lobsters Security14d ago
My Homelab Got Hacked - A Postmortem
→ No new info (linked only)
Tier B
BSI Advisories28d ago
[NEU] [hoch] Gitea: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier D
The Hacker News28d ago
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
1.27.1
CWECWE-94
PublishedAug 26, 2026
Trending Score148🔥
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20896EXPKEV
Gitea Docker image trusts spoofable reverse-proxy headers by default
Trending: 133
CRITICALCVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Trending: 12
HIGHCVE-2026-58417
REST API exposes organization membership of private organizations to public
Trending: 10
CRITICALCVE-2026-58508
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Trending: 10
HIGHCVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Trending: 10

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 26, 2026
Added to CISA KEV
Aug 26, 2026
Discovered by ZDM
Aug 26, 2026
Actively Exploited
Aug 26, 2026
Patch Available
Aug 26, 2026