PT-2026-65725 · Undefined · Undefined
CVE-2026-60004
·
Published
2026-07-29
·
Updated
2026-07-29
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
🚨 New Gitea RCE (CVE-2026-60004) lets repository writers plant a malicious Git hook and run shell commands as the Gitea service account.
On default-configured instances, outsiders can register, create a repository, and obtain the required write access.
A public PoC is available.
Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined