Skip to main content
← Back to Demos
Malware intermediate · 15 min

Gitea diffpatch RCE (CVE-2026-60004, CISA KEV) — Sandbox Detonates the Hook Planted as the Gitea Service Account (2026-09-11 CISO Daily Digest)

The 2026-09-11 CISO Daily Digest covered Shadowserver's warning that 8,393 internet-facing Gitea instances remained vulnerable to CVE-2026-60004 — a critical remote-code-execution flaw (CVSS 9.8) reported by Salesforce researcher Shai Rod, fixed in Gitea 1.27.1 on July 27 and added to CISA's Known Exploited Vulnerabilities catalog on August 25 after attackers began deploying cryptocurrency-mining malware on unpatched servers, with vulnerable instances concentrated in China, Germany and the United States. The bug lives in Gitea's diffpatch API: a submitted patch should only touch the Git index ('git apply --cached'), but sending the same patch twice forces an add/add collision that drops git apply into its three-way-merge fallback, which writes the file to disk — so anyone with ordinary repository write access (trivial where Gitea's default open registration is left on) can plant an executable Git hook (hooks/post-index-change) that Git runs as the Gitea service account — the account whose compromise the vendor advisory ties to exposure of app.ini, application secrets, database and OAuth credentials. This demo safely reproduces the payload stage of that intrusion: malicious-git-hook.sh is the hook an attacker plants — running it shows the only visible impacts, a local 'hook fired' marker file (./git-hook-fired.log) and the calculator (standing in for the attacker's command), with annotations retracing the CVE-2026-60004 chain; malicious-crafted-patch.diff is the static crafted request body that plants the hook, and malicious-win.cmd reproduces the same impact for Windows-hosted Gitea. Nothing destructive, no network callbacks; the clean control sample (clean-git-hook.sh) has the attack sequence removed and opens nothing. MetaDefender Sandbox detonates the suspicious hook script in an isolated environment, observes the command-execution behavior, and flags the implant before it can run on production developer infrastructure (MITRE ATT&CK T1059.004 — Command and Scripting Interpreter: Unix Shell).

Attack Technique

Malicious Git hook planted via a crafted diffpatch submission on a Gitea server (CVE-2026-60004: the patch is applied twice so the add/add collision forces git apply's three-way-merge fallback, writing an executable hook to disk that runs shell commands as the Gitea service account) — sandbox detonation of the hook script demonstrates the command-execution stage (T1059.004 Command and Scripting Interpreter: Unix Shell)

MITRE ATT&CK

T1059.004 ↗

Platforms

linux

File Types

.cmd.diff.sh

MetaDefender Capabilities

MetaDefender Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---