vulnhighUnderground · Vulnerability
KEV agrega CVE-2026-60004 — Gitea / Gitea
OccurredAug 25, 2026 · 00:00 UTC
DetectedAug 26, 2026 · 12:04 UTC
SourceUnderground · Vulnerability
External ref.CVE-2026-60004
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
- cve_id
- CVE-2026-60004
- vendor_product
- Gitea / Gitea
No related events in the past 48h.