[KEV] CVE-2026-60004: Gitea Code Injection Vulnerability
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
CVE · detail
- CVE-2026-60004KEVEPSS 85%NVD ↗