تخطي إلى المحتوى الرئيسي
Cyber News BleepingComputer 9 hours ago

Hackers now exploit critical Gitea flaw in code injection attacks

Bl
BleepingComputer

Gitea

Attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Like cloud-hosted GitHub or GitLab SaaS (Software as a Service) platforms, Gitea provides a full suite of DevOps tools, but it is designed to be used as a self-hosted software development platform.

Tracked as CVE-2026-60004 and reported by Salesforce security researcher Shai Rod, this code injection security flaw allows an authenticated user with repository write access to repositories hosted on vulnerable servers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint.

Get the report

View Original Report

This intelligence was aggregated from BleepingComputer.

Read on Source
Advertisement