Outdated Forgejo Instance Exploited via Git Hook to Mine Crypto on Homelab
A self-hosted Forgejo v13 server was compromised after an attacker exploited CVE-2026-60004, a vulnerability in the Gitea diffpatch endpoint that allows arbitrary file writes. The server had been running an end-of-life version since January 2026 and had open public registration enabled, giving the attacker easy initial access. Once in, the attacker planted a malicious Git hook that killed monitoring processes, disabled competing workloads, and downloaded cryptomining binaries using six different fallback methods. The owner only discovered the breach after sustained 50% CPU usage triggered system alerts. Security experts recommend disabling open signup, updating self-hosted Git platforms promptly, and restricting user ability to write Git hooks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in