Remote Code Execution Vulnerability in Forgejo by Codeberg
CVE-2026-89094
9.9CRITICAL
What is CVE-2026-89094?
Forgejo versions prior to 16.0.4 exhibit a serious vulnerability that can be exploited to execute remote code. This issue arises from improper handling of template expansion on files located in the .forgejo/template directory. Attackers can craft malicious template repositories, which, when processed by the Forgejo application, may lead to unauthorized code execution, potentially compromising the application and its environment.
Affected Version(s)
Forgejo 16.0.0 < 16.0.4
Forgejo 0 < 15.0.8
