Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-60004: Gitea Gitea

Gitea包含一個程式碼注入脆弱性,允許擁有暫存器寫入許可權的攻擊者向diffpatch API端點傳送惡意補丁,以植入可執行的Git鉤並執行 shell命令作為Gitea服務賬戶。

CISA (English)

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

廠商
Gitea
產品
Gitea
漏洞
Gitea Code Injection Vulnerability
加入日期
2026年8月25日
CISA 修補期限(美國聯邦機關)
2026年8月28日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-94

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02