The record
Written from the 2 reports below. Nothing here is unsourced.
- Gitea has patched a critical remote code execution vulnerability that let users with repository write access run shell commands on the server through malicious patch content.
- The flaw is tracked as CVE-2026-60004 with a CVSS score of 9.8 and affects Gitea versions 1.17 and later before 1.27.1, which is fixed in version 1.27.1.
- Because Gitea enables open registration by default, an outside visitor could create a normal account and repository on an unchanged installation and exploit the bug without pre-existing credentials.
- Gitea Cloud instances were upgraded automatically on July 27, and the advisory includes public proof-of-concept code but does not say the flaw has been exploited in the wild.
- A successful attack gives the privileges of the Gitea service account, potentially exposing secrets, database credentials, and reachable internal services, so self-hosted users should upgrade to 1.27.1 promptly.
What to watch next
- Whether Gitea reports any exploitation in the wild before or after the 1.27.1 fix
- Whether Gitea publishes a separate advisory or CVE for the file-inclusion issue found by Shai Rod
- Whether administrators disable open registration on installations that have not yet upgraded
What changed2
Every report on this story, newest first. Times are when each outlet published.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Subhajeet Singha
security researcher
2 quotes · 1 outlet
“Within days of the vulnerability's July 2026 disclosure, Red Heron transformed public proof-of-concept code into an automated framework capable of registering accounts, exploiting vulnerable servers, stealing repositories, and removing selected traces,”
In the article
…vulnerability, to scan thousands of instances across seven countries, turning a publicly-available exploit for the flaw into a full-fledged automated Python framework ("exp_enhanced.py") starting July 29, 2026. " Within days of the vulnerability's July 2026 disclosure, Red Heron transformed public proof-of-concept code into an automated framework capable of registering accounts, exploiting vulnerable servers, stealing repositories, and removing selected traces, " security researcher Subhajeet Singha said. "The campaign demonstrates how quickly N-day vulnerabilities in self-hosted development platforms can expose source code, credentials, secrets, and connected infrastructure."…
“The operator appears to have adapted publicly available proof-of-concept code and other open-source tools”
In the article
…can expose source code, credentials, secrets, and connected infrastructure." Singha told The Hacker News there is no evidence indicating the use of artificial intelligence (AI) to develop the exploitation framework. " The operator appears to have adapted publicly available proof-of-concept code and other open-source tools ," Singha added. In one Taiwanese environment, the threat actor has been observed progressing from a vulnerable Gitea server to root-level administrative access across a three-node Proxmox cluster. Further examination…
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Gitea instances (versions 1.17.0 - 1.27.0) remote code execution· immediate
- Affected organizations (13 targeted) source code compromise· immediate
- Security and DevOps teams patch required· days
Coverage1
All filed from IndiaSingle origin
Named India · Git · JITTERLY · Proxmox · SIXZUT · Acronis Threat Research Unit · dmpdump · Gitea · Red Heron · Shai Rod · Subhajeet Singha
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

