Corrective releases of the collaborative development platform Forgejo 16.0.4 and 15.0.8 have been published, addressing a critical vulnerability (CVE not assigned) that allows a remote attacker to execute their code on the server. Forgejo server administrators are urgently recommended to update their systems and ensure there are no signs of compromise. The vulnerability was caused by insufficient sanitization when creating a new repository from a template.
To prevent the injection of its commands when processing a user-provided template, the platform removes the .git/ subdirectory before initializing a new git repository on server. An attacker could bypass this removal and create a .git/ subdirectory with their content by manipulating variable substitution in files located in the .forgejo/template directory (for example, by injecting "..\/..\/.git/hooks" into the file path). During subsequent git repository initialization, Git applied settings from the .git/ subdirectory, which could have included operations triggering arbitrary processes. This issue has been resolved by removing the .git/ subdirectory not before variable expansion, but right before executing "git init".
In Gitea 1.25.5, a similar vulnerability (CVE-2026-25718) was fixed in February.
Source: opennet.ru
