Forgejo 16.0.4 and 15.0.8 address critical security vulnerability
Date:
Thu, 10 Sep 2026 20:05:50 +0000
Description:
The Forgejo software-forge project has announced the
release of versions 16.0.4 and 15.0.8 ,
which fixes two security vulnerabilities. One is a critical flaw that would allow remote-code execution (RCE): When generating a new repository from a template repository, Forgejo clones the
template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template , and initializes a new git repository. During this process, variable template expansion could be misused in
order to create a new .git folder, which git would adopt and incorporate during
its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is
initialized. The project recommends upgrading to the latest version as soon as possible.
======================================================================
Link to news story:
https://lwn.net/Articles/1093671/
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)