CVE-2026-60004
CRITICAL
Actively Exploited
NVDCISA KEV
CVSS Score
9.8
Severity
CRITICAL
Published
Aug 26, 2026
Vendor
unknown
This vulnerability is in the CISA Known Exploited Vulnerabilities Catalog. Active exploitation has been observed. Immediate patching is recommended.
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.