Over 8,300 Gitea servers vulnerable to code execution attacks
Nearly 8,400 Gitea servers are still unpatched for a critical security flaw that allows attackers to execute arbitrary shell commands.
Intelligence analysis by Qwen 2.5 (3B)

A critical security flaw in Gitea, a self-hosted code hosting platform, has left over 8,300 servers vulnerable to remote code execution attacks. The vulnerability, CVE-2026-60004, was reported by Salesforce and affects the diffpatch API endpoint. Gitea's security team recommends upgrading to address the issue.
Gitea is a code hosting platform. A security flaw in it lets attackers run their own code on the server. They can trick the server into running the code by tricking the server to accept it. The server is supposed to be secure, but if it's not updated, attackers can trick it into running bad code.
Analysis
{"#Gitea-Security-Flaw":"The Gitea diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. Default open registration allows unauthenticated attackers to register an account, create a new repository, and trigger the vulnerability.","#CVE-2026-60004":"The vulnerability was reported by Salesforce security researcher Shai Rod and affects the diffpatch API endpoint. Successful exploitation requires repository write access and default open registration. Gitea released version 1.27.1 to address the issue.","#Exploitation-Method":"Attackers can deploy cryptocurrency mining malware on unpatched servers. The vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."}
Key points
- Over 8,300 Gitea servers are still unpatched for a critical security flaw
- The vulnerability allows attackers to execute arbitrary shell commands
- Gitea released version 1.27.1 to address the issue
- The vulnerability is a frequent attack vector for malicious cyber actors
Once patched, the servers will be secure from this type of attack.
If attackers find a way to exploit the vulnerability, they could deploy malware on the servers.



