CVE-2026-60004: Gitea Gitea
Gitea包含一個程式碼注入脆弱性,允許擁有暫存器寫入許可權的攻擊者向diffpatch API端點傳送惡意補丁,以植入可執行的Git鉤並執行 shell命令作為Gitea服務賬戶。
CISA (English)
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
- 廠商
- Gitea
- 產品
- Gitea
- 漏洞
- Gitea Code Injection Vulnerability
- 加入日期
- 2026年8月25日
- CISA 修補期限(美國聯邦機關)
- 2026年8月28日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-94
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02