RCE in multiple forgejo ports/packages

From: <mqudsi_at_neosmart.net>
Date: Sat, 12 Sep 2026 15:06:23 UTC
Hello list,

I wanted to bring to your attention that the latest forgejo packages for
the gitea fork (both the forgejo15 and forgejo16 metapackages) on all
supported FreeBSD versions are vulnerable to a widely documented and
easy-to-reproduce RCE allowing arbitrary code execution on the host as
the forgejo user. All versions below 16.0.4 (released 2026-09-10),
including LTS builds/versions, have a bug in how template repositories
are cloned due to mishandling of variable substitution that can result
in arbitrary host reads/writes and/or command execution by any
authenticated forgejo user (and public registration is open by default).

The official description of the issue, from upstream [0]:

> Critical: fix: prevent template expansion from interfering with git
> repo initialization. When generating a new repository from a
> template repository, Forgejo clones the template repository, removes
> the .git folder, performs variable template expansion on files listed
> in .forgejo/template, and initializes a new git repository. During this
> process, variable template expansion could be misused in order to
> create a new .git folder, which git would adopt and incorporate during
> its initialization of a new git repository. A malicious template
> repository could be used to read arbitrary data from the Forgejo host,
> and to execute arbitrary processes on the Forgejo host, as a remote
> code execution attack.

The only patched versions are 15.0.8 and 16.0.4, neither of which have
been pushed to any of the FreeBSD package repos, nor are
vulnerabilities for the affected versions reported by `pkg audit`, so
ideally we’d be able to get both done soon as this RCE has been public
(and much discussed) for several days now.

Note that gitea (also available via FreeBSD ports and packages)
addressed this same issue quite some time ago and is not vulnerable.

Could someone please commit an entry to FreeBSD's VuXML and, hopefully,
work on updating the affected ports? Upstream has acknowledged the security
ramifications, but I am not aware of a CVE identifier being assigned yet,
fwiw.

[0]: https://codeberg.org/forgejo/forgejo/pulls/14300

Mahmoud Al-Qudsi
NeoSmart Technologies