Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
The Hacker News
2 weeks ago

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

By info@thehackernews.com (The Hacker News)

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.