CVE-2026-60004

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*

History

No history.

Information

Published : 2026-08-26 20:17

Updated : 2026-08-27 11:41


NVD link : CVE-2026-60004

Mitre link : CVE-2026-60004

CVE.ORG link : CVE-2026-60004


JSON object : View

Products Affected

gitea

  • gitea
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')