CVE-2026-60004 carries a CVSS 3.1 base score of 9.8 against Gitea, a self-hosted Git repository hosting platform. NVD, CISA’s own KEV entry, and the GitHub Advisory Database all independently classify it as CWE-94 (Improper Control of Generation of Code), and both the GitHub Advisory Database and NVD independently corroborate the identical CVSS vector. CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 25, 2026; VulnCheck’s KEV feed separately confirms exploitation as well — two independent sources agreeing on exploitation status, which our evidence model treats as ordinary high confidence.
Because this CVE is CISA-listed, the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.
What the flaw is
NVD’s description states the outcome plainly: Gitea before version 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. The GitHub Advisory Database, which carries a fuller technical writeup for this CVE, confirms the same root cause — the diffpatch endpoint can be abused to have Gitea install and then execute a Git hook built from repository-controlled content, meaning content that the attacker themselves supplied.
We are deliberately not reproducing that writeup’s mechanism-level or reproduction detail here. The GitHub Advisory Database entry for this CVE includes a working demonstration of exploitation; this publication reports on the existence, root cause category, and impact of vulnerabilities, and does not publish the technical means of carrying one out, regardless of what a linked source contains. Two facts from that advisory are safe to state because they describe precondition and impact rather than method: the GitHub Advisory Database states that ordinary repository write access is sufficient to trigger the flaw, and that with Gitea’s default open self-registration enabled, an unauthenticated visitor can obtain that write access simply by registering an account and creating a repository — meaning the practical attack surface can extend to anyone able to reach the instance’s registration page, not only to existing trusted contributors.
Evidence and confidence
- High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV.
- High confidence — the CVSS 9.8 score and CWE-94 classification, corroborated independently by NVD and the GitHub Advisory Database.
- High confidence — the fixed version (1.27.1), stated by both NVD and the GitHub Advisory Database.
- FIRST’s EPSS model scores this CVE at 0.86777, a 99.733rd percentile score as of our ingestion — among the highest we have seen in our recent KEV coverage, consistent with a CISA-confirmed, dual-source-corroborated, publicly documented vulnerability with a low barrier to reach (self-registration) on default configurations.
No field is in conflict between our three sources for this CVE — an unusually well-corroborated record for this batch.
Why this matters
The combination here is what elevates this beyond a typical critical CVE: a low precondition (ordinary repository write access, obtainable via self-registration on a default install), a severe outcome (remote code execution as the Gitea service account), and strong, independently corroborated evidence of both the vulnerability and its exploitation. NVD’s own record notes that successful exploitation, depending on deployment isolation, can expose the Gitea application’s own configuration secrets, database credentials, and any other services reachable from the host — a compromised Git hosting instance is a pivot point into whatever else it has credentials or network access to, not just an isolated code-hosting outage.
Any Gitea instance that allows open self-registration and has not been upgraded past 1.27.1 should be treated as exposed to an unauthenticated attacker, per the GitHub Advisory Database’s own stated precondition. Disabling open registration is a faster mitigation than a version upgrade where an immediate patch window isn’t available, though upgrading to 1.27.1 or later remains the complete fix.
Frequently Asked Questions
What is CVE-2026-60004?
A CVSS 9.8 code injection vulnerability (CWE-94) in Gitea before version 1.27.1, allowing remote code execution via the diffpatch API through installation of a malicious Git hook.
Is CVE-2026-60004 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog (added August 25, 2026) and VulnCheck’s KEV feed. Two-source agreement on exploitation is treated as high confidence in our evidence model.
Do I need to be an authenticated Gitea user to exploit this? Not necessarily. The GitHub Advisory Database states that ordinary repository write access is sufficient, and that with Gitea’s default open self-registration enabled, an unauthenticated visitor can obtain that access by registering an account and creating a repository.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.
Which version fixes this? Version 1.27.1, per both NVD and the GitHub Advisory Database.
What can I do before I’m able to upgrade? Disable open self-registration on your Gitea instance if it’s enabled. That does not fix the underlying flaw for existing accounts with write access, but it removes the no-prior-credentials attack path the GitHub Advisory Database describes.
Severity, weakness classification, and exploitation status corroborated independently across the National Vulnerability Database record for CVE-2026-60004, CISA’s Known Exploited Vulnerabilities catalog entry, and the GitHub Security Advisory. Fixed version confirmed by both NVD and the GitHub Advisory Database. Gitea’s own release announcement: release of 1.27.1. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.