{"id":32976,"date":"2026-08-27T09:15:00","date_gmt":"2026-08-27T07:15:00","guid":{"rendered":"https:\/\/itbranschen.com\/?p=32976"},"modified":"2026-08-31T19:09:08","modified_gmt":"2026-08-31T17:09:08","slug":"gitea-vulnerability-is-actively-exploited","status":"publish","type":"post","link":"https:\/\/itbranschen.com\/en\/gitea-sarbarhet-utnyttjas-aktivt\/","title":{"rendered":"Critical Gitea vulnerability is being actively exploited"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><strong>CISA warns of active exploitation of CVE-2026-60004 in the self-hosted development platform Gitea. The vulnerability could allow attackers to execute commands on the server and has been fixed in version 1.27.1.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations that run their own Gitea installations are urged to urgently check the software version and configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The US Cybersecurity Agency <strong><a href=\"https:\/\/www.cisa.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">CISA<\/a><\/strong> has added CVE-2026-60004 to its catalog of actively exploited vulnerabilities, Known Exploited Vulnerabilities. This means that the authority assesses that there is reliable evidence of actual exploitation. <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=&amp;field_date_added_wrapper=all&amp;items_per_page=All&amp;search=CVE-2026-60004&amp;sort_by=field_date_added&amp;url=\" target=\"_blank\" rel=\"noreferrer noopener\">CISA&#039;s KEV entry for CVE-2026-60004<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Malicious Git hook can be executed on the server<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability is in Gitea&#039;s <code>diffpatch<\/code>-function. Through a specially designed patch, a user with write access to a repository can install an executable Git hook.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the hook is activated, the attacker can run arbitrary commands with the same operating system privileges as the Gitea service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on how the installation is isolated, a successful attack could provide access to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gitea&#039;s configuration file and application secrets.<\/li>\n\n\n\n<li>Database information and database content.<\/li>\n\n\n\n<li>Mounted code repositories.<\/li>\n\n\n\n<li>OAuth and integration credentials.<\/li>\n\n\n\n<li>Secrets in the process&#039;s environmental variables.<\/li>\n\n\n\n<li>Other internal systems that the server can reach.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability has been given a severity rating of critical and a CVSS score of 9.8. <a href=\"https:\/\/github.com\/go-gitea\/gitea\/security\/advisories\/GHSA-rcr6-4jqh-j84m\" target=\"_blank\" data-schema-attribute=\"mentions\" rel=\"noreferrer noopener\">Gitea&#039;s official security advice<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Open registration can lower the threshold<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The attack normally requires an account with the ability to write to a repository.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, on installations where open self-registration is enabled, an external visitor can create a regular account, establish a new repository, and thus gain the required access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that the attack can in practice be carried out without a pre-existing user account on installations using this configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the exploit to work, Git 2.32 or later is also required, an enabled <code>diffpatch<\/code>-route and a temporary file space that is both writable and executable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Version 1.27.1 contains the fix<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Security Council states that Gitea versions starting from 1.17 but older than 1.27.1 are affected. The fix is included in Gitea 1.27.1, which was released on July 27, 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gitea recommends all users to upgrade as soon as possible. <a href=\"https:\/\/blog.gitea.com\/release-of-1.27.1\/\" target=\"_blank\" data-schema-attribute=\"about mentions\" rel=\"noreferrer noopener\">Gitea&#039;s information about version 1.27.1<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Updating should be combined with incident control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Since the vulnerability is now considered to be actively exploited, an upgrade should not be the only measure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations should also:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Check all internet-connected Gitea installations and their versions.<\/li>\n\n\n\n<li>Upgrade to 1.27.1 or a later available version.<\/li>\n\n\n\n<li>Limit or close open user registration if the feature is not needed.<\/li>\n\n\n\n<li>Review recently created accounts and repositories.<\/li>\n\n\n\n<li>Investigate unexpected Git hooks and changes in temporary directories.<\/li>\n\n\n\n<li>Review Gitea, system, and network logs for unusual command execution.<\/li>\n\n\n\n<li>Rotate application, database, OAuth, and integration credentials if a breach is suspected.<\/li>\n\n\n\n<li>Isolate the server and conduct a full incident analysis in case of confirmed anomalies.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/itbranschen.com\/tag\/gitea\/\" data-type=\"post_tag\" data-id=\"8545\">Gitea<\/a> is often used as a self-hosted alternative to cloud-based development platforms. A breach can therefore affect source code, credentials, automated build flows, and connected production environments.<\/p>","protected":false},"excerpt":{"rendered":"\u200b\ufeffA critical vulnerability in Gitea allows execution of malicious commands via Git hooks, puts source code and secrets at risk, and requires urgent upgrades and security measures.\ufeff\u200b","protected":false},"author":1,"featured_media":33101,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"csco_display_header_overlay":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","csco_post_video_location":[],"csco_post_video_location_hash":"","csco_post_video_url":"","csco_post_video_bg_start_time":0,"csco_post_video_bg_end_time":0,"footnotes":""},"categories":[21],"tags":[24,3068,8553,31,2515,8554,8555,8556,1013,1768,3069,751,1589,8557,8558,1056,8559,7881,7738,3075,8,3073],"itb_content_type":[8303],"class_list":["post-32976","post","type-post","status-publish","format-standard","has-post-thumbnail","category-nyheter","tag-ai","tag-cisa","tag-cve-2026-60004","tag-cybersakerhet","tag-devops","tag-fjarrkorning-av-kod","tag-git","tag-gitea","tag-incidentrespons","tag-it-branschen-2","tag-it-sakerhet-nyheter-sverige","tag-it-branschen","tag-it-kanalen","tag-kev","tag-kodinjektion","tag-oppen-kallkod","tag-patchning","tag-rce","tag-sarbarhet","tag-svensk-it-nyhetssajt","tag-sverige","tag-tech-tidningen","cs-entry","cs-video-wrap"],"_links":{"self":[{"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/posts\/32976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/comments?post=32976"}],"version-history":[{"count":0,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/posts\/32976\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/media\/33101"}],"wp:attachment":[{"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/media?parent=32976"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/categories?post=32976"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/tags?post=32976"},{"taxonomy":"itb_content_type","embeddable":true,"href":"https:\/\/itbranschen.com\/en\/wp-json\/wp\/v2\/itb_content_type?post=32976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}