← All articles

Attackers exploit a critical Gitea flaw to run code on self-hosted Git servers

CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.

Check
Upgrade Gitea to 1.27.1 or later immediately, disable open self-registration on internet-facing instances, and treat any exposed, registration-enabled server as an incident-response case rather than just a patch.
Affected
Organizations running self-hosted Gitea 1.17 through 1.27.0 (CVE-2026-60004); an attacker with repository write access, obtainable through default open registration, can execute shell commands as the Gitea service account.
Fix
Patch to a fixed release, turn off self-registration where not needed, restrict internet exposure of Gitea, and hunt patched servers for rogue Git hooks, miner processes, and other signs of compromise.