← All CVEs NewScan detects
critical

CVE-2026-60004

Gitea diffpatch API remote code execution via Git hook installation (CVSS 9.8, CISA KEV)

Severity
critical
Affected product
Gitea
Affected versions
Gitea < 1.27.1
Fixed in
Gitea 1.27.1
Added to NewScan
2026-08-27
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Gitea from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-27. Version-gated on the tech_signatures "Gitea" cookie fingerprint and its /api/v1/version version_from (see that row). Gitea before 1.27.1 allows RCE through the diffpatch API by installing a Git hook; fixed in 1.27.1. The scanner does not actively install a hook (an authenticated admin action) - this is a version-match advisory that tells the operator to patch, the same shape as the other known_vulns rows here.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →