HIGHVulnerability
Verified
Global

CISA KEV: Gitea Gitea — Gitea Code Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Analysis

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-25. Remediation due: 2026-08-28.

Indicators of Compromise (1)

CVE (1)
CVE-2026-60004
Source Attribution

Originally published by CISA KEV on Aug 25, 2026. Verified by: CISA.

Related Threats