CVE-2026-60004
KEVCRITICAL 9.8EPSS 86.8%
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 86.78% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-08-25
- Nuclei
- critical · CWE-94
- Published
- 2026-08-26
Proof-of-concept exploits (10)
- HORKimhab/CVE-2026-600044★ · 2026-07-29
- 0xBlackash/CVE-2026-600041★ · 2026-07-30
- EQSTLab/CVE-2026-600041★ · 2026-08-19
- imbas007/CVE-2026-60004-POC17★ · 2026-08-03
- gagaltotal/CVE-2026-60004-poc-gitea2★ · 2026-08-08
- fevar54/cve-2026-600040★ · 2026-08-25
- HackSpeak/CVE-2026-600041★ · 2026-08-04
- shinthink/CVE-2026-600040★ · 2026-08-03
- Sachinart/CVE-2026-60004-gitea-0day0★ · 2026-08-04
- InfoSec-DB/CVE-2026-60004-Gitea-RCE-PoC0★ · 2026-08-30