cyber

CVE-2026-60004 — Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Reported by CISA KEV
Read the complete report at CISA KEV
Verification notice

IntelMap indexes open-source reporting. This page identifies what a source reported; it does not independently confirm the claim.

INCIDENT EVOLUTION

1 recorded state

Signal first indexedP3 · 98% quality · 1 source

Explore this day in the archive →
QUALITY CONTROL

Report this signal

Reports are anonymous and retained privately for editorial review.