Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely

A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This issue affects Gitea versions 1.17 through 1.27.0 and has been resolved in version 1.27.1. The flaw resides in Gitea’s diffpatch endpoint, which is responsible for processing repository patches using Git commands. An attacker with standard […]

This article has been indexed from Cyber Security News

Read the original article: