Critical Remote Code Execution Flaw Patched in Gitea
Gitea, a self-hosted Git platform, has released a patch for a critical remote code execution vulnerability, CVE-2026-60004, with a CVSS score of 9.8. This flaw allowed users with repository write access to execute shell commands as the Gitea service account. The fix is available in version 1.27.1, and users are urged to update to prevent potential system compromise.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.