> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

[SOURCE] The Hacker News [DATE: 29/07/2026 07:47] [LANGUAGE: EN]
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
[messages.read_original_source] →