CISA confirms active exploitation of Gitea code injection bug CVE-2026-60004
CISA has added a critical Gitea vulnerability to its Known Exploited Vulnerabilities catalog after confirming attackers are exploiting it in the wild. The flaw, found in the diffpatch API endpoint, lets someone with repository write access run shell commands as the Gitea service account, and since many installations allow open self-registration, even unauthenticated attackers can gain that access simply by signing up and creating a repository. Gitea patched the issue in version 1.27.1 released July 27.