CVE-2026-60004: Gitea Code Injection Vulnerability. Gitea contains a code
Gitea Code Injection Vulnerability. Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
- CISA KEV-listed (remediation due 2026-08-28)