Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-60004 · Gitea Code Injection Vulnerability
- Identyfikator
- CVE-2026-60004
- CVSS
- 9.8 CRITICAL
- CISA KEV
- AKTYWNIE WYKORZYSTYWANE
- Producent
- Gitea
- Produkt
- Gitea
- Dodano do KEV
- 2026-08-25
- Termin CISA
- 2026-08-28
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.