CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- Affected products
- Gitea
- Gitea
- < 1.27.1
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 84.6% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2026-08-26
CVE-2026-60004 at NVD
21 known exploits for CVE-2026-60004
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-60004
CVE-2026-60004
CVE-2026-60004
CVE-2026-60004-gitea-0day
CVE-2026-60004-poc-gitea
CVE-2026-60004
cve-2026-60004
CVE-2026-60004-POC
CVE-2026-60004
CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
CVE-2026-60004 β Updated!
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004
Exploit for CVE-2026-60004