{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-60004",
  "revision": 1,
  "title": "Gitea — Code Injection Through Diffpatch Git Hook Installation",
  "summary": "Gitea before 1.27.1 lets a user with write access to a repository send a crafted patch to the diffpatch endpoint that plants an executable Git hook. The hook then runs shell commands on the server as the Gitea service account, giving full remote code execution.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.86777,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-08-25",
    "prerequisites": "Network access to the Gitea diffpatch endpoint and write access to a repository on the instance"
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Gitea 1.27.1"
    ]
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade Gitea to 1.27.1 or later now; until then restrict who can push to repositories and audit repositories on the server for unexpected Git hooks.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-60004",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-60004",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-60004",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60004",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://github.com/0xBlackash/CVE-2026-60004"
    },
    {
      "type": "exploit",
      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m"
    },
    {
      "type": "writeup",
      "url": "https://www.runzero.com/blog/gitea/"
    }
  ],
  "published_at": "2026-08-26T20:17:56.010Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "gitea",
    "git",
    "code-injection",
    "rce"
  ]
}
