New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Source: The Hacker News
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.
Tracked as CVE-2026-60004 (CVSS score: 9