Impact
Forgejo processes ActivityPub messages, but the logic that verifies the HTTP Signature does not enforce that the signing key matches the actor value declared in the activity JSON. The router validates the signature and then later handlers read the actor field from the payload without binding it to the verified key. This allows an external actor to sign an activity with a legitimate key and claim any actor identity of their choice, so the activity appears to come from that user. The flaw does not enable account takeover or modification of content; it only undermines identity integrity by misattributing activities.
Affected Systems
Forgejo releases 13.0.0 through 16.0.4 are vulnerable when federation is enabled by setting "[federation] ENABLED = true". Any installation that exposes its federation endpoints for ActivityPub communication is affected, regardless of the number of users or repositories.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% implies a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely by an adversary who can host a valid ActivityPub actor and key pair, sign messages, and send them to the federation endpoint. No privileged local access or elaborate social engineering is required.
OpenCVE Enrichment