Bottom line: Attackers with repository write permissions can execute shell commands as the Gitea service account in versions 1.17–1.27.0 via Git Hooks; fix available in 1.27.1.
Gitea has patched a critical remote code execution vulnerability that allows users with repository write permissions to execute Git Hooks as a service account. The vulnerability CVE-2026-60004 affects versions from 1.17 through 1.27.0 with a CVSS score of 9.8.
The vulnerability CVE-2026-60004 allows users with ordinary write permissions on a repository to inject malicious patch content into active Git Hooks and thereby execute shell commands. The attacker does not require an administrative account, only normal access to a project. This enables privilege escalation to the Gitea service account with potentially far-reaching permissions on the host system.
Affected versions are Gitea 1.17 and later through and including 1.27.0. With a CVSS score of 9.8, the vulnerability is classified as highly critical. The patch is included in version 1.27.1.
CISOs should audit all Gitea instances in self-hosted environments for version 1.27.1 or later and upgrade accordingly. Special attention should be paid to systems with multiple users or integration into CI/CD pipelines, as the execution contexts can have significant implications. If a timely update is not possible, access to repository write permissions—especially for external or less trusted accounts—should be restricted.
Source: thehackernews.com · Published 29 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.