Impact
Forgejo versions prior to 16.0.4 allow a restricted API token to invoke the "allow maintainer edit" feature in a way that was not intended, enabling the bearer of such a token to elevate privileges and modify repository configuration settings without being explicitly granted that level of access. This flaw creates an unauthorized modification vector that could be exploited to change settings, potentially exposing code or affecting repository behavior.
Affected Systems
Users running Forgejo before version 16.0.4 are vulnerable. The issue applies to all instances of the Forgejo repository management system that rely on the restricted API token mechanism for authentication.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall severity, and there is no EPSS score available, suggesting low but not negligible exploit probability. The vulnerability is not listed in CISA's KEV catalog, and no public exploits have been reported. An attacker would need possession of a restricted API token and knowledge of the affected API endpoint. The impact is confined to the scope of the token bearer, but misconfiguration could lead to unintended repository alterations.
OpenCVE Enrichment