Gitea: Critical Vulnerability CVE-2026-60004 Detected, Immediate Update to Version 1.27.1
Critical Gitea vulnerability CVE-2026-60004 allows remote code execution. Update self-hosted instances to version 1.27.1 immediately to secure your server.
Illustrative image generated with AI
Introduction
On July 28, 2026, the Gitea team published a security advisory for a severe vulnerability affecting versions from 1.17 to 1.27.0 of the self-hosted Git platform. The flaw, identified as CVE-2026-60004 and rated with a CVSS of 9.8 (Critical), allows arbitrary command execution on the server by exploiting the /diffpatch API. The discovery was made by researcher Shai Rod (NightRang3r), who also publicly released a proof-of-concept. The fix was integrated on July 26 and made available on July 27 with the release of version 1.27.1. Gitea Cloud instances have been automatically updated; all on-premise instance administrators must apply the update with the utmost urgency.
Technical Analysis
The weakness resides in the handling of patches applied through the /diffpatch API endpoint. During processing, Gitea performs a temporary bare clone of the target repository. An attacker can send the same patch twice: this forces a three-way merge conflict, triggering the writing of an executable Git hook – named post-index-change – inside the hooks directory of the bare clone. Git, by default, executes any script present in that directory. In this way, a malicious user can inject arbitrary code that will be executed with the same privileges as the Gitea service account.
To exploit the vulnerability, authentication and write permissions on at least one repository are required. However, Gitea's standard configuration allows open registration without approval: anyone can create an account and their own repository, making the attack practically executable even by external parties with no prior credentials. Exploitation complexity is low and requires no user interaction.
Impact
A successful attack enables remote code execution (RCE) as the Gitea system user. This allows reading environment variables, stealing database credentials, OAuth tokens, repository SSH keys, and accessing any file or network service visible from the server. The infrastructure is at risk of complete lateral compromise. The critical severity is justified by the combination of remote exploitability, low required privileges, and no user interaction.
Mitigation
- Priority action: immediately update Gitea to version 1.27.1 or higher. The patch modifies the patching process by converting the temporary clone from bare to non-bare, thus eliminating the possibility of malicious hook injection.
- Temporary containment: Disabling open registration (set
REGISTRATION_DISABLED = trueor equivalent) prevents new hostile users from creating accounts and repositories. This measure does not fix the vulnerability and does not protect against already registered users with write permissions. - Partial risk reduction: Mounting the filesystem used for temporary files with the
noexecoption can hinder hook execution, but it is not a complete solution and should not be considered a substitute for updating. - No alternative workarounds are available.
The same 1.27.1 release also includes a mitigation for a file inclusion issue in the Org-mode renderer, currently without a specific CVE.
FAQ
1. Which Gitea versions are affected by CVE-2026-60004?
All versions from 1.17 (inclusive) up to 1.27.0 (inclusive). Version 1.27.1, published on July 27, 2026, contains the fix.
2. Is authentication required to exploit the flaw?
Yes, an account with write permissions on a repository is needed. However, since Gitea's default configuration allows free registration, an attacker can create an account and a repository independently, making the exploit effectively accessible remotely without pre-existing credentials.
3. Has the vulnerability already been used in real attacks?
As of July 29, 2026, no active exploitation campaigns have been reported. The availability of a public proof-of-concept nonetheless significantly elevates the concrete risk. Organizations are urged to apply the update without delay.
Sources
This article is an original reworking based on the sources below.




