Gitea security advisory (AV26-845)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-845 Date: August 25, 2026 As of August 14, 2026, Gitea is affected by vulnerabilities in the following product: Gitea Prior to 1.27.1 On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Remote Code Execution via diffpatch Git Hook Installation Gitea 1.27.1 is released Gitea 1.27.2 is released CISA KEV: CVE-2026-60004
CSIRTS triage
- What
- A code injection vulnerability in the diffpatch Git hook allows attackers with repository write access to execute arbitrary shell commands as the Gitea service account.
- Who is affected
- Gitea instances running versions before 1.27.1 with repositories that accept untrusted patches.
- Urgency
- Critical; actively exploited as of August 2026 and added to CISA KEV catalog; allows full system compromise.
- Action
- Immediately upgrade to Gitea 1.27.1 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Gitea
Get an email when a new Gitea advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/gitea-security-advisory-av26-845
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-60004Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60004 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-60004: Gitea Code Injection Vulnerabilitycisa-kev
- high[NEW] [high] Gitea: Vulnerability allows code executioncert-bund
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24
- unknownDell security advisory (AV26-843)2026-08-24