CVE-2026-89094: Critical severity Forgejo Forgejo vulnerability
Published Sep 10, 2026
·Updated
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
Affected Software
1 affected component
Forgejo Forgejo<16.0.4
Event History
Sep 10, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Forgejo deployments are affected?
Forgejo versions before 16.0.4 are affected.
2
What does an attacker need to exploit this issue?
The attacker needs low-level privileges and a crafted template repository. User interaction is not required, and the attack can be performed remotely.
3
What version should be used to remediate the issue?
Upgrade Forgejo to version 16.0.4 or later.