discovered 06 Aug 2026
CVE-2026-60004-POC
→ View on GitHubThe CVE-2026-60004-POC tool provides a proof-of-concept for exploiting a pre-authentication remote code execution vulnerability in Gitea versions 1.17 through 1.27.0, with a CVSS score of 9.8. This exploitation occurs via the `diffpatch` API endpoint, allowing attackers to inject malicious Git hooks that execute arbitrary commands by manipulating Git's patch processing. Notable features include two operational modes for automation and the ability to retrieve command output directly from the target server after exploitation.