CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3413

As cited

Copy frozen at (site build).

vulnerabilities

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, a self-hosted Git platform, patched a critical remote code execution vulnerability tracked as CVE-2026-60004 with a CVSS score of 9.8. The flaw allows users with repository write access to create Git hooks that execute shell commands with the privileges of the Gitea service account. The vulnerability affects versions 1.17 through 1.27.0, with a fix available in version 1.27.1.

Why it matters: Gitea administrators and users running versions before 1.27.1 should upgrade immediately, as any repository contributor can achieve code execution on the underlying server.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, a self-hosted Git platform, patched a critical remote code execution vulnerability tracked as CVE-2026-60004 with a CVSS score of 9.8. The flaw allows users with repository write access to create Git hooks that execute shell commands with the privileges of the Gitea service account. The vulnerability affects versions 1.17 through 1.27.0, with a fix available in version 1.27.1.

Why it matters: Gitea administrators and users running versions before 1.27.1 should upgrade immediately, as any repository contributor can achieve code execution on the underlying server.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, a self-hosted Git platform, patched a critical remote code execution vulnerability tracked as CVE-2026-60004 with a CVSS score of 9.8. An attacker with repository write access can create a malicious Git hook to execute shell commands under the Gitea service account. The flaw affects versions 1.17 through 1.27.0 and is resolved in version 1.27.1.

Why it matters: Organizations running Gitea instances must upgrade to version 1.27.1 immediately, as any user with write access to a repository can achieve remote code execution with active exploitation confirmed in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary