CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.