• solrize@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 days ago

    From TFA:

    CVE-2026-60004 allows attackers to abuse Gitea’s diffpatch endpoint to install and execute a Git hook from repository-controlled content.

    “An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user,” the maintainers explained last month, after the vulnerability had been patched in Gitea v1.27.1.