{"id":"GO-2026-6433","summary":"Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev","details":"Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev","aliases":["BIT-gitea-2026-60004","CVE-2026-60004","GHSA-rcr6-4jqh-j84m"],"modified":"2026-09-10T15:25:46.385543493Z","published":"2026-09-10T14:48:42Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6433"},"references":[{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60004"},{"type":"WEB","url":"https://blog.gitea.com/release-of-1.27.1"},{"type":"WEB","url":"https://github.com/0xBlackash/CVE-2026-60004"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/commit/470d34b1de87d901bd9135564d5ee18c0d339e82"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/commit/d7bc52beeadff4be5f5690de4d5de42abd10affe"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/38637"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/38638"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.1"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004"},{"type":"WEB","url":"https://www.runzero.com/blog/gitea"}],"affected":[{"package":{"name":"code.gitea.io/gitea","ecosystem":"Go","purl":"pkg:golang/code.gitea.io/gitea"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.17.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6433.json"}},{"package":{"name":"gitea.dev","ecosystem":"Go","purl":"pkg:golang/gitea.dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.27.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6433.json"}}],"schema_version":"1.9.0","credits":[{"name":"NightRang3r"}]}