Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
0 results for “self-hosted Git”
Hackers now exploit critical Gitea flaw in code injection attacks
CISA has added a critical-severity vulnerability in Gitea—a self-hosted Git service—to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
Aug 26, 2026
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
A critical unauthenticated file-read vulnerability (CVE-2026-59774, CVSS 9.8) in Gitea versions 1.22.1–1.27.0 allowed attackers to exfiltrate arbitrary server files using only a public repository and malicious Org-mode markup — exposing sensitive data without authentication or write privileges.
Aug 5, 2026
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004, CVSS 9.8) allowing repository writers to execute arbitrary shell commands as the service account via malicious Git hooks.
Jul 29, 2026
Hackers exploit critical auth bypass in Gitea Docker image
A critical authentication bypass vulnerability in the official Gitea Docker image is under active exploitation, enabling attackers to impersonate any user—including administrators—posing immediate risk to self-hosted code repositories.
Jul 10, 2026