CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-60004: Critical Gitea RCE via Git Hook Planting

July 29, 2026

A critical remote code execution vulnerability in Gitea allows users with repository write access to plant a Git hook and execute shell commands as the Gitea service account. Affects versions 1.17 to before 1.27.1. Fixed in version 1.27.1.