CVE-2026-60004 is a critical remote code execution vulnerability affecting Gitea versions prior to 1.27.1. The vulnerability exists in the diffpatch API, which can be exploited to install malicious Git hooks, ultimately allowing an attacker to execute arbitrary code on the server. A patch was released in Gitea version 1.27.1. A public proof-of-concept exploit has been published on GitHub. The vulnerability has been assigned a high criticality rating and is documented in a GitHub Security Advisory under GHSA-rcr6-4jqh-j84m. Organizations running self-hosted Gitea instances are urged to upgrade immediately to mitigate the risk of remote compromise.