Gitea, a popular open-source Git hosting platform, released version 1.27.1 to address CVE-2026-60004, a critical remote code execution vulnerability. The flaw could be exploited via the diffpatch endpoint with repository write access, which is obtainable by default due to open registration.