HackerFeeds

CyberSecurity News

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

The Hacker News
· July 29, 2026

AI summary

A critical remote code execution vulnerability has been patched in Gitea, a self-hosted Git platform. The flaw allows a user with ordinary repository write access to create a live Git hook from attacker-controlled patch content, enabling them to run shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, affects Gitea versions 1.17 and later, up to version 1.27.1. The issue is fixed in version 1.27.1 of Gitea. This vulnerability can be exploited by repository writers to execute malicious commands. The patch resolves the remote code execution risk.

Read the full article at The Hacker Newsthehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.