A self-hosted Forgejo instance was compromised via CVE-2026-60004, an RCE vulnerability in Gitea's diffpatch endpoint that Forgejo inherited. The attacker exploited an open sign-up form (which the author thought was disabled) and an outdated, EOL v13 image tag to create a malicious repo with a Git hook that downloaded and executed a cryptocurrency miner. The postmortem walks through log analysis, the exploit's similarity to a public GitHub POC and Nuclei template, and remediation steps: rolling back to a clean backup, upgrading to v16, disabling open signups and local auth, and plans to restrict per-container network access.
Community take
Updated
8
comments
Discussion focuses on whether the CVE should have been separately attributed to Forgejo, and pivots into a broader debate about homelab security practices like network isolation, authenticating proxies, and choosing image tags with longer security-update windows.
15% positive
45% mixed
40% skeptical
Deep diveQuestions this post answers
What is CVE-2026-60004 and how does it allow remote code execution in Forgejo or Gitea?
CVE-2026-60004 is a remote code execution vulnerability in Gitea's (and thus Forgejo's) diffpatch API endpoint that lets an attacker push a malicious Git post-index-change hook script to gain code execution on the server. Exploitation involves signing up for an account, creating a repo with the crafted hook, then sending at least two POST requests to /api/v1/repos/USER/REPO/diffpatch to trigger it. It was patched in the latest v15 LTS and v16 releases of Forgejo. Track Gitea and Forgejo security advisories on daily.dev before an unpatched RCE turns into a live incident.
Why would pinning a Docker image to a specific version number leave a self-hosted git server vulnerable to attack?
Because Forgejo does not publish a rolling latest image tag, a container pinned to a specific version like v13 will never surface an available-update notification the way latest-tagged containers do, so it can silently sit on an end-of-life release long after a critical patch ships. In one case a v13 instance stayed vulnerable to a diffpatch RCE for six months after v13 reached end of life in January 2026. Developers self-hosting pinned container versions can watch for EOL and CVE alerts through daily.dev.
What does malware do after exploiting a git server RCE to deploy a crypto-miner payload?
After gaining code execution, the second-stage shell script kills processes with guard in the name and any process using over 80% CPU (evading antivirus and rival miners), disables their systemd entries, picks a writable download location among /tmp, HOME, and PWD, detects CPU architecture, downloads an architecture-specific binary via curl, wget, Python, or Perl fallbacks, then executes it in memory and deletes the file from disk. VirusTotal identified the resulting binaries as known crypto-miners. Homelab operators hardening against post-exploitation payloads can follow security writeups like this via daily.dev.
Share this post