Follow

Over 8,300 internet-exposed Gitea servers remain vulnerable to active code injection attacks Shadowserver counted 8,393 exposed instances still unpatched against CVE-2026-60004. The flaw lets an authenticated attacker execute shell commands via Gitea’s diffpatch API, and default self-registration can provide the required repository write access. Gitea fixed the issue in 1.27.1 in Gitea’s advisory .

github.com/go-gitea/gitea/secu

· · vexo · 0 · 0 · 0
Sign in to participate in the conversation
Merovingian Club

A club for red-pilled exiles.