<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Hackers now exploit critical Gitea flaw in code injection attacks]]></title><description><![CDATA[<p dir="auto">Attackers have begun actively exploiting a critical-severity vulnerability in the self-hosted Git service <strong>Gitea</strong>, according to an alert from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw enables remote code execution through crafted git hooks, allowing unauthenticated attackers to inject malicious code into repositories under certain configurations.</p>
<p dir="auto">The vulnerability affects all versions of Gitea prior to the latest patched release. Successful exploitation depends on the attacker having access to a repository where they can create or modify git hooks, and the service must be running with a user account that has sufficient filesystem permissions. Once exploited, the attacker can execute arbitrary commands on the underlying server, potentially leading to full compromise of the hosting instance and any data stored within it.</p>
<p dir="auto">CISA has added this flaw to its Known Exploited Vulnerabilities catalog, signaling that active exploitation is occurring in the wild. The agency strongly recommends that administrators review their Gitea deployments and apply the available security update immediately. If immediate patching is not feasible, mitigations include restricting access to repository creation and hook management, as well as running the service with the least-privileged user account possible.</p>
<ul>
<li>Affected: Gitea versions before the latest security release</li>
<li>Action: Update to the newest version immediately</li>
<li>Additional mitigation: Disable or restrict git hook usage for untrusted users</li>
<li>Monitor: Check server logs for unusual repository hook activity</li>
</ul>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Is your team already tracking Gitea instances, and how are you handling the rollout of this patch across your self-hosted environments?</p>
]]></description><link>https://xploitlk.com/topic/107/critical-hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 14:24:02 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/107.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 26 Aug 2026 12:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>