Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-60004: Gitea Gitea

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Vendor
Gitea
Product
Gitea
Vulnerability
Gitea Code Injection Vulnerability
Date added
Aug 25, 2026
CISA due date (U.S. federal agencies)
Aug 28, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-94

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02