Hackers now exploit critical Gitea flaw in code injection attacks

Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are actively exploiting CVE-2026-60004, a critical code injection flaw in Gitea that can let authenticated users run arbitrary shell commands on vulnerable servers. Because default Gitea installations allow open registration, unauthenticated attackers can create accounts and repositories to abuse the flaw, prompting CISA to order urgent patching and Gitea to release version 1.27.1. #Gitea #CVE-2026-60004 #CISA

Keypoints

  • CISA says CVE-2026-60004 is being actively exploited in Gitea.
  • The flaw allows arbitrary shell command execution through the diffpatch API.
  • Default open registration can let unauthenticated attackers gain write access.
  • Gitea released version 1.27.1 on July 27 to fix the vulnerability.
  • CISA ordered U.S. federal agencies to patch affected systems within three days.

Read More: https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/