Security
Forgejo 16.0.4 and 15.0.8 address critical security vulnerability
jzb LWN.net
2 views
The Forgejo software-forge project has announced the
release of versions 16.0.4
and 15.0.8,
which fixes two security vulnerabilities. One is a critical flaw that would
allow remote-code execution (RCE):
When generating a new repository from a template repository, Forgejo clones the
template repository, removes the .git folder, performs variable template
expansion on files listed in .forgejo/template, and initializes a new git
repository. During this process, variable template expansion could be misused in
order to create a new .git folder, which git would adopt and incorporate during
its initialization of a new git repository. A malicious template repository
could be used to read arbitrary data from the Forgejo host, and to execute
arbitrary processes on the Forgejo host, as a remote code execution attack. To
address this issue, after variable expansion is completed, any existing .git
folder is removed from the directory before the git repository is initialized.
The project recommends upgrading to the latest version as soon as
possible.
Read original: https://lwn.net/Articles/1093671/
← Previous
Bitemporal CIEDE2000 Calibration: Event-Sourced PostgreSQL Queues and Low-Latency SSE Telemetry for Shadow’s 24fps Multimodal Synthesis Core
Next →
AI Scan for pull request APIs in public preview
Related
PicoCTF Mod 26 Writeup — Brute-Force a Caesar Cipher
Security
3
Dev.to (EN Zone)
Mandiant Founder Kevin Mandia Joins Amazon Board
Security
1
SecurityWeek
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Security
1
SecurityWeek
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Security
4
SecurityWeek
Comments0
No comments yet — be the first