CVE-2026-89094
Forgejo versions older than 16.0.4 can run arbitrary code when a user creates a specially crafted template repository. The flaw is due to improper handling of template files in the .forgejo/template directory.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Forgejo installations running a version earlier than 16.0.4. Users who host or use Forgejo for code hosting and collaboration are at risk.
Real-world impact
An attacker could execute arbitrary code on the server hosting Forgejo, potentially taking full control of the system, stealing data, or installing malware.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is exploitable over the network with low effort, requires only low privileges, and can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
- 011. Upgrade Forgejo to version 16.0.4 or later.
- 022. Restart the Forgejo service to apply the update.
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.