CVE-2026-60004: Gitea Code Injection Vulnerability. Gitea contains a code

Gitea Code Injection Vulnerability. Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Related briefings

Browse the CVE database

Read the full analysis on IntelFusions