Gitea Code Injection Flaw Actively Exploited, CISA Warns
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Gitea vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. Tracked as CVE-2026-60004, the flaw affects Gitea a popular self-hosted Git service used by developers and enterprises to manage source code repositories.
The vulnerability, classified as a code injection issue (CWE-94), allows attackers with repository write access to exploit the diffpatch API endpoint by submitting a malicious patch. This patch plants an executable Git hook on the server, enabling arbitrary shell command execution under the privileges of the Gitea service account. Notably, the attack does not require administrative access only write permissions, a level of access commonly granted to collaborators.
Once deployed, the malicious hook executes automatically during routine Git operations, providing attackers with a stealthy method to escalate control over the server. While CISA has not confirmed links to ransomware campaigns, the agency has set a remediation deadline of August 28, 2026, for federal agencies and stakeholders, following its addition to the KEV catalog on August 25, 2026.
Organizations using self-hosted or cloud-based Gitea instances are urged to apply vendor-issued patches immediately, audit repository access controls, and review recent patch and hook activity. The flaw underscores the risks to software supply chains, as self-hosted Git platforms remain prime targets for attackers seeking to inject malicious code. Compliance with Binding Operational Directive (BOD) 26-04 is required, with cloud-hosted instances subject to additional guidance or potential discontinuation if mitigations are unavailable.
Source: https://cybersecuritynews.com/gitea-code-injection-vulnerability-exploited/
Elestio cybersecurity rating report: https://www.rankiteo.com/company/elestio
"id": "ELE1787804624",
"linkid": "elestio",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations using self-hosted '
'or cloud-based Gitea instances',
'industry': 'Technology/Software Development',
'name': 'Gitea',
'type': 'Software Provider'}],
'attack_vector': 'Malicious patch submission via diffpatch API endpoint',
'customer_advisories': 'Organizations using self-hosted or cloud-based Gitea '
'instances are urged to apply patches immediately.',
'date_publicly_disclosed': '2026-08-25',
'description': 'CISA has added a critical Gitea vulnerability '
'(CVE-2026-60004) to its Known Exploited Vulnerabilities (KEV) '
'catalog after confirming active exploitation in the wild. The '
'flaw allows attackers with repository write access to exploit '
'the diffpatch API endpoint by submitting a malicious patch, '
'planting an executable Git hook on the server, enabling '
'arbitrary shell command execution under the privileges of the '
'Gitea service account.',
'impact': {'operational_impact': 'Arbitrary shell command execution under '
'Gitea service account privileges',
'systems_affected': 'Gitea self-hosted and cloud-based instances'},
'initial_access_broker': {'backdoors_established': 'Malicious Git hook'},
'investigation_status': 'Active exploitation confirmed',
'lessons_learned': 'The flaw underscores the risks to software supply chains, '
'as self-hosted Git platforms remain prime targets for '
'attackers seeking to inject malicious code.',
'post_incident_analysis': {'corrective_actions': 'Patch management, access '
'control audits, and '
'monitoring of Git hooks',
'root_causes': 'Code injection vulnerability '
'(CWE-94) in diffpatch API '
'endpoint'},
'recommendations': 'Apply vendor-issued patches immediately, audit repository '
'access controls, and review recent patch and hook '
'activity.',
'references': [{'source': 'CISA Known Exploited Vulnerabilities (KEV) '
'Catalog'}],
'regulatory_compliance': {'regulations_violated': 'Binding Operational '
'Directive (BOD) 26-04',
'regulatory_notifications': 'CISA KEV catalog '
'addition'},
'response': {'containment_measures': 'Apply vendor-issued patches, audit '
'repository access controls, review '
'recent patch and hook activity',
'remediation_measures': 'Apply vendor-issued patches'},
'stakeholder_advisories': 'Federal agencies and stakeholders must remediate '
'by August 28, 2026.',
'title': 'Gitea Code Injection Flaw Actively Exploited, CISA Warns',
'type': 'Code Injection',
'vulnerability_exploited': 'CVE-2026-60004 (CWE-94)'}