Close Menu
    What's Hot

    Chelsea transfer news: Danny Welbeck and Jordan Henderson good for experience but striker needs game time, says Paul Merson | Football News

    These 5 pillars helped our company thrive for 60 years

    How exposed is the UK economy to the second China shock?

    Facebook X (Twitter) Instagram
    Trending
    • Chelsea transfer news: Danny Welbeck and Jordan Henderson good for experience but striker needs game time, says Paul Merson | Football News
    • These 5 pillars helped our company thrive for 60 years
    • How exposed is the UK economy to the second China shock?
    • Virgin Media O2 owners weigh options to slash £22bn debt pile
    • Robinhood: In A Volatile Market, This Company Continues To Grow Rapidly (NASDAQ:HOOD)
    • New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
    • Iran War Shows European Countries Are Middle Powers
    • OpenAI Hack Shows the Genie Is Out of the Bottle
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

    adminBy adminJuly 30, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 29, 2026Vulnerability / DevOps

    New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

    Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.

    Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The vulnerable API call requires authentication and repository write permission. But Gitea enables registration by default, so an outside visitor can create a normal account and repository on an unchanged installation, then exploit the bug without pre-existing credentials.

    Upgrading to 1.27.1 is the fix. Gitea said on July 27 that Gitea Cloud instances would be upgraded automatically. Gitea’s July 28 advisory does not say the flaw has been exploited in the wild, but it includes public proof-of-concept (PoC) code.

    Disabling open registration can remove the public account-creation path while the update is deployed, but it does not fix the flaw or protect against existing users with repository write access.

    Cybersecurity

    The flaw was reported by security researcher Shai Rod, who goes by NightRang3r. Gitea credits NightRang3r as the reporter in its advisory.

    Gitea’s affected route invokes reqToken(), which rejects requests without a signed-in user. The no-prior-credentials path comes from the project’s default configuration, which leaves registration open, requires neither email nor manual approval, does not mark new users as restricted, and imposes no default repository-creation limit.

    The bug sits in the POST /api/v1/repos/{owner}/{repo}/diffpatch endpoint. According to Gitea’s security advisory, the endpoint applies a supplied patch inside a shared bare temporary clone. Vulnerable builds invoke git apply with --index, --recount, --cached, and --binary, adding the -3 three-way fallback option when the server runs Git 2.32 or later.

    An attacker submits the same patch twice to create an add/add collision. The three-way fallback then checks the indexed path out even though the operation uses --cached. Because the temporary clone is bare, its root is $GIT_DIR. An executable file placed at hooks/post-index-change therefore lands in Git’s hook directory and becomes active. Git runs it while updating the index.

    The PoC signs in with a normal account, creates an initialized private repository, sends the malicious patch twice, and retrieves the command output. It needs no outbound callback. The hook stores the output in Git objects, creates a branch containing the result, and lets the attacker fetch it over authenticated smart HTTP.

    As of July 29, 2026, none of the cited primary sources reports whether the flaw was exploited before or after version 1.27.1 became available.

    Successful exploitation gives the attacker the privileges of the Gitea operating-system account. Depending on how the instance is isolated, Gitea said that could expose application and environment secrets, mounted repositories, database credentials and contents, OAuth credentials, and reachable internal services.

    Cybersecurity

    Exploitation still requires repository write access, Git 2.32 or later, an enabled diffpatch route, and a writable, executable temporary filesystem. Default registration lets an outsider obtain the required write access on an unchanged installation.

    The fix is easy to miss in the changelog. Gitea changed the temporary clone from bare to non-bare. The code comment explicitly warns that Git commands using --index may operate on the working tree. The change was merged and backported on July 26, 2026.

    Version 1.27.1 shipped on July 27, and the security advisory followed on July 28. The release notes listed the change under MISC as “refactor: git patch apply,” not under SECURITY.

    Rod had previewed the RCE alongside a separate file-inclusion issue, with a PoC retrieving /etc/passwd from a Gitea 1.27.0 host. That issue appears to correspond to a separate change included in 1.27.1 that altered Gitea’s Org-mode renderer so #+INCLUDE paths are returned as plain text instead of being read from the server’s filesystem. Gitea has not published a separate advisory or CVE for the file-inclusion issue.

    Commands Git Gitea hook Lets plant RCE Repository run Shell writers
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleIran War Shows European Countries Are Middle Powers
    Next Article Robinhood: In A Volatile Market, This Company Continues To Grow Rapidly (NASDAQ:HOOD)
    admin
    • Website

    Related Posts

    73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

    July 30, 2026

    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    July 30, 2026

    Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

    July 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Chelsea transfer news: Danny Welbeck and Jordan Henderson good for experience but striker needs game time, says Paul Merson | Football News

    These 5 pillars helped our company thrive for 60 years

    How exposed is the UK economy to the second China shock?

    Virgin Media O2 owners weigh options to slash £22bn debt pile

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by