CVE-2026-60004: Gitea Gitea
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
- ベンダー
- Gitea
- 製品
- Gitea
- 脆弱性
- Gitea Code Injection Vulnerability
- 追加日
- 2026/08/25
- CISA対応期限(米国連邦機関向け)
- 2026/08/28
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-94
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02