news.mlab.sh
Back to the feed
vulnerability

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

High
Image: The Hacker News
Summary

A critical remote code execution (RCE) vulnerability in Gitea allows a user with repository write access to plant a Git hook and execute shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026-60004, affects Gitea versions 1.17 through 1.27.0 and is addressed in version 1.27.1. The flaw can be exploited without prior credentials due to default registration settings, potentially exposing sensitive data like application secrets and database credentials.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.