tag
Code-Hosting
CVE-2026-60004
web
HIGH 8.8
Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)
CVE-2026-60004 is an authenticated remote code execution vulnerability in the Gitea diffpatch API. The endpoint applies a supplied patch with git apply --cached, which should only update the index and never write files to disk. However, by sending the same…
Patched
2026-08-09