A code injection flaw in Gitea’s diffpatch endpoint lets a user with repository write access install a Git hook and run arbitrary shell commands as the Gitea service account.
Read more about Emerging Threat: (CVE-2026-60004) Gitea Remote Code Execution via diffpatch Git Hooks