
Critical RCE Vulnerability Patched in Gitea Git Platform
CybersecurityVulnerabilitiesSoftwareSecurityExploits
A critical remote code execution (RCE) vulnerability (CVE-2026-60004, CVSS score: 9.8) was patched in Gitea, a self-hosted Git platform. The flaw allows users with repository write access to exploit attacker-controlled patch content to create a live Git hook, enabling shell command execution as the Gitea service account. The vulnerability affects Gitea versions 1.17 and later, up to but not including 1.27.1, with the fix implemented in version 1.27.1. No specific exploitation timeline or attack instances were disclosed in the report.