PT-2026-65725 · Gitea · Gitea

·

CVE-2026-60004

·

Published

2026-07-28

·

Updated

2026-08-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gitea versions 1.17 through 1.27.0
Description A critical code injection flaw exists in the services/repository/files/patch.go file. An attacker with write access to a repository can exploit the diffpatch API endpoint to install a malicious executable Git hook, allowing the execution of arbitrary shell commands with the privileges of the Gitea operating-system user. If open user registration is enabled, unauthenticated external attackers can register an account, create a repository, and gain the necessary write permissions to trigger the exploit.
Real-world incidents have been documented where this issue was exploited to deploy cryptocurrency-mining payloads. In one observed attack, the exploit chain from account creation to the deployment of a crypto-mining dropper took approximately 11 seconds. The malicious activity involved identifying CPU-intensive processes, terminating competing miners, and downloading architecture-specific binaries.
Recommendations Update Gitea to version 1.27.1 or later. As a temporary workaround, disable or restrict access to the diffpatch API endpoint. Review and restrict open user registration and repository write permissions.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10703
BIT-GITEA-2026-60004
CVE-2026-60004
GHSA-RCR6-4JQH-J84M

Affected Products

Gitea