Exploited in the wild Gitea rce web-app
CISA Warns of Exploited Gitea Vulnerability
CVE Tools coverage
CISA has identified active exploitation of a remote code execution flaw in the self-hosted Git hosting platform Gitea. The vulnerability, designated as CVE-2026-60004, enables attackers with repository write access to inject malicious Git hooks through the diffpatch API endpoint. This defect was remediated in release version 1.27.1, and the agency has mandated that federal systems apply the patch immediately.