Analysis
Gitea's diffpatch endpoint plants a Git hook, and the hook does the rest
CVE-2026-60004 turns repository write access into shell execution as the Gitea service account. The interesting part is not the injection — it is that Git hooks are executable files sitting inside a directory your developers write to all day.
CVE-2026-60004T1195.002T1059.004T1546