Overview
What is CVE-2026-60004?
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Gitea Code Injection Vulnerability
CISA lists CVE-2026-60004 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Gitea Gitea.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.