EIP-2026-104263
PRE-CVEGitea 1.12.5 - Remote Code Execution (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104263. PoCs published by Podalirius.
AI-analyzed exploit summary This exploit demonstrates an authenticated remote code execution vulnerability in Gitea versions 1.1.0 to 1.12.5 by abusing Git hooks (specifically post-receive hooks) to execute arbitrary commands on the server. The PoC automates repository creation, hook configuration, and payload delivery via Git operations.
Description
Gitea 1.12.5 - Remote Code Execution (Authenticated)
Exploits (1)
This exploit demonstrates an authenticated remote code execution vulnerability in Gitea versions 1.1.0 to 1.12.5 by abusing Git hooks (specifically post-receive hooks) to execute arbitrary commands on the server. The PoC automates repository creation, hook configuration, and payload delivery via Git operations.