Tag

#CVE-2026-60004

1 published story tagged with CVE-2026-60004.

highAPT / Nation-StateAug 25, 2026·2 min read

Attackers exploit Gitea code injection flaw to execute shell commands via API

Attackers are actively exploiting a code injection flaw in Gitea to run shell commands with service account privileges. This vulnerability requires repository write access to succeed.