CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2026-60004

CVSS 9.8v3.1pub. 2026-08-26upd. 2026-08-27

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Gitea

    APP
    Gitea
    1.17.0 – 1.27.1 (excl.)

CISA KEV — detailsi

Vendori
Gitea
Producti
Gitea
Added to KEVi
August 25, 2026
Remediation deadline (US Federal)i
August 28, 2026(overdue)
Required action (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA descriptioni

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 28 sierpnia 2026
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-20750CRITICAL9.1PL ✓same product

Gitea: nieprawidłowa walidacja własności projektów organizacji

CVE-2026-20912CRITICAL9.1PL ✓same product

Gitea: nieautoryzowany dostęp do załączników z prywatnych repozytoriów

CVE-2026-20897CRITICAL9.1PL ✓same product

Gitea: nieautoryzowane usuwanie blokad Git LFS między repozytoriami

CVE-2022-42968CRITICAL9.8PL ✓same product

Gitea: brak sanityzacji refs prowadzący do wstrzyknięcia argumentów git

CVE-2021-45330CRITICAL9.8PL ✓same product

Gitea: nieprawidłowe unieważnianie sesji umożliwia przejęcie uprawnień