Gitea security advisory (AV26-845)
CISA added CVE-2026-60004, an actively exploited RCE via diffpatch Git hook installation in Gitea, to the KEV catalog; users should upgrade past 1.27.1.
Canadian Centre for Cyber Security advisory AV26-845 reports that Gitea versions prior to 1.27.1 are affected by CVE-2026-60004, remote code execution via diffpatch Git hook installation. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 25, 2026, indicating observed exploitation. Fixed releases 1.27.1 and 1.27.2 are available, and administrators should upgrade promptly.
- CVE-2026-60004: RCE via diffpatch Git hook installation
- CISA added the flaw to the KEV catalog on August 25, 2026
- Gitea prior to 1.27.1 affected; 1.27.1 and 1.27.2 fix it
- Canadian Cyber Centre urges immediate patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-60004 | Unauthenticated RCE in Gitea via diffpatch API Git Hook Injection Gitea before 1.27.1 contains a critical code injection flaw (CWE-94) in the diffpatch API that allows remote code execution by causing the installation of a Git hook. An attacker can submit a crafted request through the diffpatch API to plant a Git hook, which then executes arbitrary shell commands on the server when Git operations run; the CVSS vector indicates the attack requires no authentication or user interaction, while public reporting describes attackers with repository write access planting hooks to run shell commands. Successful exploitation yields full server compromise (confidentiality, integrity, and availability all rated high), and observed attacks have reportedly dropped a cryptocurrency miner. All Gitea deployments running versions prior to 1.27.1 are affected, with internet-facing instances at greatest risk; public scans identified over 8,300 vulnerable Gitea servers. The flaw is actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-25, and EPSS estimates an 86.8% probability of exploitation within 30 days. Do: Upgrade Gitea to version 1.27.1 or later immediately; organizations subject to BOD 26-04 must apply the vendor mitigation or discontinue use of unpatched cloud-hosted instances. Until patched, limit internet exposure of Gitea servers and inspect repository hook directories for unauthorized or recently modified hooks that could serve as persistence. Check for signs of compromise, including unexpected processes or cryptocurrency-miner activity, since in-the-wold attacks reportedly deploy a miner. | 9.8 | 87% | KEV PoC ×4 |
| moderate≈8,300+ internet-exposed Gitea servers (public scan count) |
Serial Number: AV26-845 Date: August 25, 2026 As of August 14, 2026, Gitea is affected by vulnerabilities in the following product: Gitea Prior to 1.27.1 On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Remote Code Execution via diffpatch Git Hook Installation Gitea 1.27.1 is released Gitea 1.27.2 is released CISA KEV: CVE-2026-60004
This source does not provide full text. Read it at cyber.gc.ca.