CVE-2026-60004
CRITICAL CISACVSS Score
N/A
Severity
CRITICAL
Source
CISA
Published
Aug 25, 2026
Description
Gitea โ Gitea: Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.