Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.