Gitea Security Update Advisory (CVE-2026-60004)
Overview
A security update has been released to address a vulnerability in Gitea. This vulnerability is identified as CVE-2026-60004.
Affected Products
Affected products are Gitea versions 1.17 Through 1.27.1.
Vulnerability Details
A remote code execution vulnerability (CVE-2026-60004) occurs in Gitea’s diffpatch endpoint due to the installation and execution of Git hooks (features that automatically run when specific actions occur in a repository).
Recommended Action
A Vulnerability Patch has been released in the latest update. You must update to Gitea 1.27.1 Following the instructions on the reference website.