ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8

CVE-2026-60004 · Gitea Code Injection Vulnerability

Identyfikator
CVE-2026-60004
CVSS
9.8 CRITICAL
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
Gitea
Produkt
Gitea
Dodano do KEV
2026-08-25
Termin CISA
2026-08-28
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.