a Gitea admin's hosting bill flagged 70% CPU usage. that's how he found the hackers

A bug that lets anyone with a free account plant a git hook is now CISA's problem — and it started with a cryptominer, not a headline.

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-60004 (CVSS 9.8) lets a repository writer plant a malicious git hook via Gitea's diffpatch endpoint and get shell-level command execution.

The short version

Every Gitea release from 1.17 up to but not including 1.27.1 is vulnerable — patch to 1.27.1 immediately.

The short version

Open registration turns this from an insider bug into an anonymous one: an attacker can create the account they need on the spot.

The short version

CISA added it to the Known Exploited Vulnerabilities catalog on August 25, 2026, with a three-day deadline for federal systems.

The short version

The first confirmed exploitation dropped a cryptomining payload, not ransomware — but the access it grants goes much further.

If you can't patch today

Disabling open registration removes the walk-up-and-register path, but it does not fix the underlying flaw — anyone who already has an account with repo-write access can still trigger it. Treat it…

Aliteq

Read the full story

a Gitea admin's hosting bill flagged 70% CPU usage. that's how he found the hackers

Read the full story on Aliteq