The flaw is in services/repository/files/patch.go, where Gitea applies attacker-controlled patches in a shared bare temporary clone using Git apply with --index, --cached, and --binary, and adds -3 on Git 2.32 or newer. An add/add collision can cause Git's three-way fallback to check out a path from the patch even though the operation uses --cached. Because the root of a bare repository is $GIT_DIR, an executable file at hooks/post-index-change becomes a live Git hook. Git invokes the hook while writing the index, allowing repository-controlled content to execute shell commands as the Gitea OS user. The advisory identifies Git 2.32 or newer, an enabled diffpatch route, and a writable and executable temporary filesystem as conditions. The impact beyond the service account depends on host isolation and the permissions granted to the Gitea account.