CVE-2026-60004

Summary

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Affected Software

VendorProductVersion RangeStatus
GiteaGitea1.17 < 1.27.1affected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

References