Impact
Forgejo before version 16.0.4 is vulnerable to remote code execution due to mishandling of template expansion on files located in the ".forgejo/template" directory. An attacker who can create a crafted template repository can execute arbitrary code on the server. The flaw is rooted in the improper handling of template rendering, identified as CWE-1336.
Affected Systems
The affected vendor is Forgejo, product Forgejo. All installations running any are vulnerable. If the exact version is unknown, any instance of Forgejo below 16.0.4 should be considered at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, indicating critical severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote malicious template repository. Once a template is rendered, the attacker can execute code with the privileges of the Forgejo service, potentially compromising the entire system.
OpenCVE Enrichment