Gitea <= 1.27.0 - Pre-Auth Remote Code Execution
CVE-2026-60004
Verified
Description
Gitea versions 1.17 through 1.27.0 contain a remote code execution vulnerability in the diffpatch endpoint caused by an add/add collision that writes an executable Git hook into the bare repository's GIT_DIR. An attacker with write access can execute arbitrary commands as the Gitea service account, exploit requires only open registration for unauthenticated access.
Severity
Critical
CVSS Score
9.8
Exploit Probability
24%
Affected Product
gitea
Published Date
August 3, 2026
Template Author
0x_akoko
CVE-2026-60004.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-60004
CWE ID:
cwe-94
Remediation Steps
Update to Gitea version 1.27.1 or later.