CVSS 9.8, and "Self-Registration" Reveals Its Fangs—Vulnerabilities in GitHub Alternative Gitea Begin to Be Exploited
On August 25th, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a serious vulnerability in the self-hosted Git platform "Gitea" to its catalog of known exploited vulnerabilities (KEVs). What engineers should pay attention to is the technical mechanism of this vulnerability itself, and the fact that actual attacks were confirmed approximately one month after the patch was released.
Positioning as a "Self-Hosted Alternative" to GitHub
Gitea is an open-source Git platform that allows code repository hosting and management services like GitHub and GitLab to be run on their own servers. It is widely adopted by companies and development teams that want to complete source code management within their own infrastructure.
The vulnerability in question, CVE-2026-60004, is classified as an extremely severe vulnerability with a CVSS (Common Vulnerability Scoring System) score of 9.8 (out of 10). This vulnerability existed in Gitea's "diffpatch" API endpoint (a function for processing differential patches).
Shell commands can be executed if you have "write permissions" to the repository
Let's look at the technical mechanism. According to Gitea's developers, an attacker with normal write access to the repository can send a malicious patch to the diffpatch API endpoint, thereby embedding an executable "Git hook" (a script that is automatically executed when a specific Git operation occurs). When this hook is executed, the command is executed with the privileges of the Gitea service account.
In other words, by exploiting legitimate repository write permissions, it is possible to execute arbitrary shell commands on the server running that Gitea instance. This vulnerability affects Gitea versions 1.17 through 1.27.0 and was fixed in version 1.27.1, released at the end of July.
Self-Registration Feature Breaks the "Authentication Required" Premise
The reason this vulnerability is considered particularly dangerous lies in Gitea's default settings. Many Gitea instances have the "self-registration" feature enabled, allowing anyone to freely create an account. The necessary condition for an attacker is "write access to the repository," but in environments where this self-registration feature is enabled, an external attacker can create an account and repository themselves, thus fulfilling this condition.
In other words, while this vulnerability appears to be a relatively limited risk of "privilege escalation by authenticated users," in reality, it has a much broader target: "any Gitea server that is publicly accessible on the internet and allows self-registration can be attacked from the outset by an external third party."
Actual Damage Cases Reported on a Russian Technology Blog
Specific cases demonstrating the actual exploitation of this vulnerability have also been reported. On the Russian collaborative blogging platform Habr, a full-stack developer publicly announced that a self-hosted Gitea instance operated by their organization had been compromised through this vulnerability.
The developer became aware of the breach after receiving a notification from their hosting provider that the virtual server's CPU usage had exceeded 70% for an extended period. It is believed that the attackers exploited this vulnerability to deploy malicious programs for cryptocurrency mining on the system.
Attribution "Unknown"—Understanding the Meaning of KEV Addition
What should be noted in this case is that the details of the specific attack campaign that led CISA to add this vulnerability to its KEV catalog have not been made public. CISA's notification does not mention the attacker's identity, the affected organization, or the specifics of the attack campaign. It is unclear whether the case reported on Habr directly led to CISA's decision, or whether CISA independently confirmed evidence of exploitation within the US.
Security firm SOC Prime advises that, given this situation, defenders should pay attention to behavioral indicators such as "suspicious account creation," "unusual calls to the diffpatch API," "creation of unexpected Git hooks," and "unusual processes or communications originating from the Gitea service."
The "August 28th" Deadline for Federal Agencies
CISA has instructed U.S. federal civilian agencies to fix this vulnerability by August 28th. This is in line with CISA's standard response deadline framework for known exploit vulnerabilities (BOD 26-04). However, this deadline is an administrative directive for federal agencies, and Gitea instances operated by private companies and individuals are required to respond with the same urgency.
What Engineers Should Note
For development teams self-hosting Gitea, this news is a clear warning that the top priority should be "upgrading to version 1.27.1 or later." In addition, if you have enabled the self-registration feature, reviewing its necessity and disabling it if unnecessary would be an effective additional measure.
For instances that may have already been compromised, it is recommended to preserve evidence such as access logs, repository metadata, hook files, and system logs before performing destructive cleanup. Unlike large cloud services like GitHub, self-hosted development infrastructure places all responsibility for patching and monitoring on the operator themselves. This case serves as a stark reminder of the weight of that responsibility.