Skip to main content
CyberConfirmedHighDevelopingFeatured
8.7

Critical Gitea RCE vulnerability (CVE-2026-60004) allows unauthorized shell command execution

A remote code execution vulnerability in Gitea allows users with repository write access to execute arbitrary shell commands as the service account. The exploit is particularly severe because default configurations permit public registration, enabling unauthenticated attackers to gain the necessary write permissions. A public proof-of-concept is available, increasing the risk of immediate exploitation.

The Hacker News1 day agoscoCredibility 52%View source

Score Breakdown

Mosaic Score8.7
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found