← Back to blog

Critical Gitea RCE Flaw Actively Exploited to Deploy Cryptominers

A critical remote code execution flaw in Gitea is being actively exploited by threat actors. Organizations using the self-hosted Git service should patch immediately.

TL;DR

  • CVE-2026-60004 is a critical RCE flaw in Gitea with a CVSS score of 9.8.
  • Attackers are exploiting it to deploy cryptominer-like payloads.
  • CISA has issued a warning about active exploitation attempts.
  • Organizations should update Gitea installations to the latest patched version.
  • Threat requires only standard repository write access to execute commands.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about active exploitation of a critical remote code execution (RCE) vulnerability in Gitea, a popular self-hosted Git service platform. CVE-2026-60004 carries a severe CVSS score of 9.8, making it a prime target for malicious actors.

Security researchers have confirmed that attackers are leveraging this flaw to deploy cryptominer-like payloads on compromised systems. The vulnerability allows threat actors with standard write permissions to a repository to execute arbitrary shell commands, potentially leading to full system compromise and unauthorized resource hijacking.

Vulnerability Details

  • CVE-2026-60004 affects Gitea versions prior to the latest security release
  • Exploitation requires only basic repository write access, not administrative privileges
  • Successful exploitation grants attackers full shell command execution capabilities
  • The flaw has been assigned a critical CVSS score of 9.8 out of 10

Impact and Recommendations

  • Active exploitation campaigns are deploying cryptocurrency mining malware
  • Organizations running self-hosted Gitea instances are at immediate risk
  • CISA recommends immediate patching to the latest Gitea version
  • Administrators should audit repository access permissions and monitor for suspicious activity
  • Consider implementing network segmentation and enhanced logging for Git infrastructure

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.