CVE-2026-60004
CRITICALCVSS 9.8/10Actively Exploited
Last modified
CVE-2026-60004 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.. CISA has confirmed active exploitation in the wild.
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Gitea | Gitea | >= 1.17, < 1.27.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-60004?
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
How severe is CVE-2026-60004?
CVE-2026-60004 has a CVSS score of 9.8/10 (CRITICAL severity). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2026-60004?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59998sshd in OpenSSH before 10.4 has an undocumented security-rel…6.5
- CVE-2026-59999In sshd in OpenSSH before 10.4, DisableForwarding=yes was su…7.5
- CVE-2026-6000A vulnerability was found in code-projects Online Library Ma…4.3
- CVE-2026-60000sshd in OpenSSH before 10.4 allows remote attackers to cause…7.5
- CVE-2026-60001sshd in OpenSSH before 10.4 does not always honor the minimu…6.5
- CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a …9.4
- CVE-2026-60005NGINX Plus and NGINX Open Source have a vulnerability in the…8.2
- CVE-2026-60007In Eclipse Milo versions 0.6.0 through 1.1.4, username-token…7.4
- CVE-2026-60009In Eclipse Theia versions up to and including 1.73.1, the `@…8.8
- CVE-2026-6001Authorization bypass through User-Controlled key vulnerabili…8.8
- CVE-2026-60011Sharp and Toshiba Tec MFPs (multifunction printers) fail to …6.9
- CVE-2026-6002Improper neutralization of Script-Related HTML tags in a web…8.8
Are you affected by CVE-2026-60004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
