macc /
FR EN
Demander un échange
← Retour à la console
Élevée CISA KEV · USA CVE-2026-60004

Gitea Code Injection Vulnerability

Publié

Description

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.