critical
CVE-2026-60004
Gitea diffpatch API remote code execution via Git hook installation (CVSS 9.8, CISA KEV)
- Severity
- critical
- Affected product
- Gitea
- Affected versions
- Gitea < 1.27.1
- Fixed in
- Gitea 1.27.1
- Added to NewScan
- 2026-08-27
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Gitea from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-27. Version-gated on the tech_signatures "Gitea" cookie fingerprint and its /api/v1/version version_from (see that row). Gitea before 1.27.1 allows RCE through the diffpatch API by installing a Git hook; fixed in 1.27.1. The scanner does not actively install a hook (an authenticated admin action) - this is a version-match advisory that tells the operator to patch, the same shape as the other known_vulns rows here.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →