Critical Gitea RCE Flaw Actively Exploited to Deploy Cryptominers
A critical remote code execution flaw in Gitea is being actively exploited by threat actors. Organizations using the self-hosted Git service should patch immediately.
TL;DR
- CVE-2026-60004 is a critical RCE flaw in Gitea with a CVSS score of 9.8.
- Attackers are exploiting it to deploy cryptominer-like payloads.
- CISA has issued a warning about active exploitation attempts.
- Organizations should update Gitea installations to the latest patched version.
- Threat requires only standard repository write access to execute commands.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about active exploitation of a critical remote code execution (RCE) vulnerability in Gitea, a popular self-hosted Git service platform. CVE-2026-60004 carries a severe CVSS score of 9.8, making it a prime target for malicious actors.
Security researchers have confirmed that attackers are leveraging this flaw to deploy cryptominer-like payloads on compromised systems. The vulnerability allows threat actors with standard write permissions to a repository to execute arbitrary shell commands, potentially leading to full system compromise and unauthorized resource hijacking.
Vulnerability Details
- CVE-2026-60004 affects Gitea versions prior to the latest security release
- Exploitation requires only basic repository write access, not administrative privileges
- Successful exploitation grants attackers full shell command execution capabilities
- The flaw has been assigned a critical CVSS score of 9.8 out of 10
Impact and Recommendations
- Active exploitation campaigns are deploying cryptocurrency mining malware
- Organizations running self-hosted Gitea instances are at immediate risk
- CISA recommends immediate patching to the latest Gitea version
- Administrators should audit repository access permissions and monitor for suspicious activity
- Consider implementing network segmentation and enhanced logging for Git infrastructure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.