
CVE-2026-60004-poc-gitea
CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)



Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Proof of Concept for CVE-2024-32002

A script to exploit CVE-2020-14144 - GiTea authenticated Remote Code Execution using git hooks

hook repo for cve-2024-32002

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

Working Python test and PoC for CVE-2018-11776, includes Docker lab


CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.


RCE hook