Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
https://www.securityweek.com/cisa-warns-of-exploited-gitea-vulnerability/
https://www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/
https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html
https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html
https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
https://github.com/fevar54/cve-2026-60004
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/babakizo420/security-research
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m