Login
← All news

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

The Hacker News

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Read the full story on The Hacker News https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
Most attacks like this land on ordinary sites rather than chosen targets: an unpatched plugin, a backup nobody ever restored, an account without two-factor. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage for you.