New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.

Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

1,741 “informed” consents with one click? GDPR complaint filed

1,741 “informed” consents with one click? GDPR complaint filed Source: Hacker News

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to

A Biography of Lee Holloway, the Architect of Cloudflare’s Technology (Part 1)

A Biography of Lee Holloway, the Architect of Cloudflare’s Technology (Part 1) Source: Hacker News