Gitea Security Update Advisory (CVE-2026-60004)

Gitea Security Update Advisory (CVE-2026-60004)

Overview


A security update has been released to address a vulnerability in Gitea. This vulnerability is identified as CVE-2026-60004.

Affected Products


Affected products are Gitea versions 1.17 Through 1.27.1.

Vulnerability Details


A remote code execution vulnerability (CVE-2026-60004) occurs in Gitea’s diffpatch endpoint due to the installation and execution of Git hooks (features that automatically run when specific actions occur in a repository).

Recommended Action


A Vulnerability Patch has been released in the latest update. You must update to Gitea 1.27.1 Following the instructions on the reference website.