What is CVE-2026-60004?
A critical remote code execution (RCE) vulnerability has been patched in the self-hosted Git platform Gitea. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. It is recommended to update Gitea to the latest version immediately.
Azərbaycanca: Gitea öz-özünə host edilən Git platformasında kritik uzaqdan kod icrası (RCE) zəifliyi aşkarlanıb. Repoya yazma icazəsi olan adi istifadəçi patch məzmununu canlı Git hook-a çevirərək Gitea xidmət hesabı ilə shell əmrləri icra edə bilər. Dərhal Gitea-nı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What level of access does an attacker need to exploit CVE-2026-60004?
The attacker only needs a user account with ordinary repository write access.
What can an attacker gain by successfully exploiting CVE-2026-60004?
The attacker can execute shell commands as the Gitea service account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.