Security · 2h ago
Critical Gitea RCE Lets Repository Writers Execute Shell Commands
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004, CVSS 9.8) affecting versions 1.17 to 1.27.1. Users with repository write access can turn patch content into a Git hook and run shell commands as the Gitea service account. The fix is available in version 1.27.1.
Meridian48 take
While Gitea patched quickly, the flaw underscores the risk of granting write access in self-hosted Git platforms, where a seemingly minor permission can lead to full server compromise.
Read the full reporting
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands →
The Hacker News
gitearemote-code-execution