중요 Gitea 원격 코드 실행 취약점이 악용되고 있다.
미국 사이버 보안 인프라 보안청(CISA)은 최근 패치된 Gitea의 심각한 보안 취약점이 악용되고 있다는 경고를 발표했다. 해당 취약점(CVE-2026-60004)은 CVSS 점수 9.8로, 공격자가 일반적인 쓰기 권한만으로도 임의 셸 명령을 실행할 수 있게 한다. 사용자는 이번 취약점에 대한 즉각적인 대응이 필요하다.
Critical Gitea RCE vulnerability is being actively exploited.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about active exploitation targeting a recently patched critical security flaw in Gitea. The vulnerability, CVE-2026-60004, has a CVSS score of 9.8 and allows an attacker with ordinary write access to execute arbitrary shell commands. Users are urged to take immediate action regarding this vulnerability.