Skip to content
Critical RCE Vulnerability in Forgejo Fixed in Versions 16.0.4 and 15.0.8

Critical RCE Vulnerability in Forgejo Fixed in Versions 16.0.4 and 15.0.8

First seen 26 Sep 2026, 18:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •CVE-2026-89094 allows RCE via crafted template repositories in Forgejo.
  • •Versions 16.0.4 and 15.0.8 released to patch the critical vulnerability.
  • •The vulnerability has a CVSS score of 9.9, indicating high severity.

On September 10, 2026, a critical remote code execution vulnerability (CVE-2026-89094) was discovered in Forgejo, affecting versions prior to 16.0.4. The flaw allowed attackers to exploit the repository creation process by manipulating template repositories to execute arbitrary code on the server. This vulnerability received a CVSS score of 9.9, indicating its severity. The Forgejo team released versions 16.0.4 and 15.0.8 on September 26, 2026, to address this issue. The fix involved changing the order of operations during repository initialization to prevent the exploitation of the .git folder. Users are advised to upgrade immediately to mitigate risks. The vulnerability requires user authentication to exploit, limiting its immediate impact but still posing a significant threat to self-hosted instances.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-03
CVE-2026-27660 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-58432 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-10
CVE-2026-89094 published
A critical RCE vulnerability in Forgejo was disclosed, affecting versions prior to 16.0.4.
Dev.To
2026-09-26
Forgejo releases patches
Versions 16.0.4 and 15.0.8 were released to fix the critical RCE vulnerability.
lwn.net

More articles in this cluster (4)

Following this threat?

Track CVE-2026-27660 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed