
[CIVN-2026-0426] Remote Code Execution Vulnerability in Gitea
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Gitea
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Gitea versions from 1.17 to 1.27.0
Overview
A critical vulnerability has been reported in Gitea which may allow an attacker to execute remote code on the targeted system.
Target Audience:
All organizations and individuals using Gitea.
Risk Assessment:
Critical risks of unauthorized access to source code and repositories.
Impact Assessment:
Potential for sensitive information disclosure, unauthorized modification of repositories, credential compromise, and complete system/server compromise.
Description
Gitea is an open-source, self-hosted Git repository management platform, similar to GitHub or GitLab. It provides code hosting, pull requests, issue tracking, and access management.
This vulnerability exists in the Giteas diffpatch endpoint and can be exploited to install and execute a Git hook from repository-controlled content.
Successful exploitation of this vulnerability could allow an attacker with repository write access to a repository to execute arbitrary shell commands as the Gitea service account.
Solution
Apply appropriate updates as mentioned by the vendor:
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
Vendor Information
Gitea
https://gitea.com/
References
Github
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
CVE Name
CVE-2026-60004
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVjrQACgkQ3jCgcSdc
ys8YNA/+JXh2DVsyQbb34hy77zEeoGJ54E5lgZGyQou2G0X8USps/sPqs7S/0iIq
xZHxvT87WyzH5lKH9aFaVWljBmCepeXPpIVQ7XRqdM0LmtAYGnQBFEooIyHPQ1S/
LMZ+d0N+/nD2oYvr3Qown3OWFhokIepiE1BAYbNY6uWVCyp+f89mHCV6TGb3T/7I
/R4SGqA6btxh2JGCoyUdzvMwnyIGpdWIlM2aWm4XbMsRN69AFwe70+MsA5Hjel83
+wQ15DzqIdPZt16Dd4veFQD9v85JJLeAjUR/KRBQs1e3vELDtUymDy44DQhBrcqn
sdsh0VcPGcWmsUBLIN1jsMuURkP1/lma9r8L5ocwrM/gMp+YSC741L0HVov16KV9
whwRSjMotUQ+j50iSNmL0ZSPIoGm4kaqJViRq4auVnjKmDIybi2H5hhkRH9eKTag
n/KuSO+wWjzG4OAACMZIUxYbZg0LsBvqJak8aUWQMfJpJVPt9NOE839JGV0UgTkd
5B13Hh7jIkdfGVf/GLYB9wkds6EYyZh4Ya4e0obTkw6Ai0Sx2qcpIrrihrv3jy6L
gBHlp8cM8PsExtMogZxpRlQd6rAO3WE/nEgpYvJg0gBADaxeGiuxxQ1en4F1w+9Y
lCVgSi/uhYsw3jQAo5OccKXqTlGaBB7eLEDRiar4gB5TQ9fzKJM=
=ik3P
—–END PGP SIGNATURE—–


