You must log in or register to comment.
From TFA:
CVE-2026-60004 allows attackers to abuse Gitea’s diffpatch endpoint to install and execute a Git hook from repository-controlled content.
“An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user,” the maintainers explained last month, after the vulnerability had been patched in Gitea v1.27.1.