Summary
CVE-2026-60004 is a critical remote code execution vulnerability in Gitea, a self-hosted Git service, caused by improper handling of patch content in the diffpatch API that allows an attacker to install a malicious Git hook. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and affects Gitea versions 1.17 through versions before 1.27.1.
Technical details
- Root cause: In
services/repository/files/patch.go, when a patch is applied twice to a bare temporary repository clone, an add/add collision occurs. Git’s three-way merge fallback extracts the indexed path even though the operation uses--cached, and because the bare clone’s root is$GIT_DIR, an attacker-controlled entry can be written tohooks/post-index-change. - Trigger conditions: Requires Git 2.32 or newer on the server, the
diffpatchroute enabled, a writable/executable temporary filesystem, and repository write access — which can be obtained via self-registration if open account registration is enabled. - Attack vector: Network — an attacker submits crafted patch content through the
diffpatchAPI to plant a live Git hook that executes on subsequent index writes. - Impact: Arbitrary command execution as the Gitea service account, potentially exposing application secrets, database credentials, OAuth tokens, and mounted repository data.
Affected software
- Gitea versions ≥ 1.17 and < 1.27.1
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Gitea to version 1.27.1 or later, which fixes this issue.
- If patching is not immediately possible:
- Disable open self-registration to prevent untrusted users from obtaining repository write access.
- Restrict or disable the
diffpatchAPI route where feasible. - Ensure the temporary filesystem used by the Gitea service is not writable/executable by untrusted processes.
- Monitor repository and hook activity for unexpected
post-index-changehook creation.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Meta tag (
keywords):go,git,self-hosted,gitea - Raw response body:
© Gitea Version:

