• Forgejo 16.0.4 and 15.0.8 address critical security vulnerability

    From LWN.net@1337:1/100 to All on Thu Sep 10 21:15:05 2026
    Forgejo 16.0.4 and 15.0.8 address critical security vulnerability

    Date:
    Thu, 10 Sep 2026 20:05:50 +0000

    Description:
    The Forgejo software-forge project has announced the
    release of versions 16.0.4 and 15.0.8 ,
    which fixes two security vulnerabilities. One is a critical flaw that would allow remote-code execution (RCE): When generating a new repository from a template repository, Forgejo clones the
    template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template , and initializes a new git repository. During this process, variable template expansion could be misused in
    order to create a new .git folder, which git would adopt and incorporate during
    its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is
    initialized. The project recommends upgrading to the latest version as soon as possible.

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/1093671/


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)