Gitea RCE Flaw Lets Write-Access Users Execute Shell Commands via Malicious Git Hook
A critical vulnerability in Gitea (CVE-2026-60004) allows any user with repository write access to execute arbitrary shell commands as the Gitea service account by exploiting an add/add merge collision that triggers a planted Git hook. The flaw is particularly dangerous because Gitea's default configuration enables open registration, meaning external attackers can self-register and gain the write access needed to exploit the vulnerability without any prior authorization. This highlights how a combination of a code-level flaw and permissive default settings dramatically expands an attacker's reach. Organizations running self-hosted Gitea instances as part of their software supply chain or CI/CD pipelines face significant risk, as compromise of the service account could cascade into broader infrastructure access.
Tactical Insight
Immediate actions
- Upgrade all Gitea instances to version 1.27.1 or later to patch CVE-2026-60004 immediately.
- Disable open/public registration on Gitea instances unless explicitly required for your use case.
- Audit current repository write-access permissions and revoke any unnecessary or overly broad access grants.
Configuration hardening
- Review and restrict Gitea's default configuration settings, enforcing invite-only or SSO-based registration.
- Run the Gitea service account with the least-privileged OS user account possible to limit blast radius if exploited.
- Implement Git hook allowlisting or disable server-side hooks for untrusted repositories where feasible.
Detection measures
- Monitor Gitea service account process activity for unexpected shell executions or child processes.
- Enable and centralize Gitea audit logs, alerting on new user registrations, repository creation, and patch submissions from new accounts.
- Integrate your Gitea host into a vulnerability management platform to receive automated alerts for future CVEs.