Critical Gitea Flaw Lets a Self-Registered Account Turn a Git Patch Into Remote Code Execution
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
Signal
9 articles covering "git"
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
GitHub Desktop 3.6.0, released June 26, brings a graphical worktree workflow and routes Copilot into commit messages and merge conflicts, with a model picker and BYOK.
Released June 29, the update extends the experimental git history command, adds inotify-based filesystem monitoring on Linux, and lets git push write to a group of remotes at once.
Jujutsu 0.42.0, released June 4, moves to the mimalloc allocator, drops several long-deprecated command options, and adds multi-revision support to jj show.
GitLab's next-generation source code management, shown at its Transcend event, keeps the Git protocol but rebuilds the backend so agents query repos server-side instead of cloning them.
CVE-2026-3854 let any authenticated user run code on GitHub's backend with a single git push. GitHub patched github.com in two hours on March 4; public disclosure on April 28 found most Enterprise Server instances still vulnerable.
Git 2.54, released April 20, introduces a new history-editing command inspired by Jujutsu, config-based hooks, geometric repacking by default, and a pluggable object database built over two years and roughly 400 commits.
Forgejo 15.0 lands as the project's new LTS release with repository-scoped access tokens, reusable workflow expansion, OpenID Connect support, and ephemeral runners.
Git 2.53 defaults Rust support in both build systems and unlocks geometric repacking for partial clones, setting the stage for a Git 3.0 release by late 2026.