CVE-2026-60004 is a code injection vulnerability in Gitea, a self-hosted Git service. An attacker with repository write access can exploit the diffpatch API endpoint by sending a malicious patch that plants an executable Git hook. This allows the attacker to execute arbitrary shell commands as the Gitea service account, potentially leading to full server compromise. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog under BOD 26-04, which mandates prioritizing security updates based on risk. Federal agencies are required to remediate this vulnerability per BOD 26-04 directives. Forensics triage requirements are also outlined in CISA's implementation guidance. The issue is tracked at NVD and has a dedicated GitHub security advisory.