CyberSecurity News
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
AI summary
A critical remote code execution vulnerability has been patched in Gitea, a self-hosted Git platform. The flaw allows a user with ordinary repository write access to create a live Git hook from attacker-controlled patch content, enabling them to run shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, affects Gitea versions 1.17 and later, up to version 1.27.1. The issue is fixed in version 1.27.1 of Gitea. This vulnerability can be exploited by repository writers to execute malicious commands. The patch resolves the remote code execution risk.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

