RCE in multiple forgejo ports/packages
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 12 Sep 2026 15:06:23 UTC
Hello list, I wanted to bring to your attention that the latest forgejo packages for the gitea fork (both the forgejo15 and forgejo16 metapackages) on all supported FreeBSD versions are vulnerable to a widely documented and easy-to-reproduce RCE allowing arbitrary code execution on the host as the forgejo user. All versions below 16.0.4 (released 2026-09-10), including LTS builds/versions, have a bug in how template repositories are cloned due to mishandling of variable substitution that can result in arbitrary host reads/writes and/or command execution by any authenticated forgejo user (and public registration is open by default). The official description of the issue, from upstream [0]: > Critical: fix: prevent template expansion from interfering with git > repo initialization. When generating a new repository from a > template repository, Forgejo clones the template repository, removes > the .git folder, performs variable template expansion on files listed > in .forgejo/template, and initializes a new git repository. During this > process, variable template expansion could be misused in order to > create a new .git folder, which git would adopt and incorporate during > its initialization of a new git repository. A malicious template > repository could be used to read arbitrary data from the Forgejo host, > and to execute arbitrary processes on the Forgejo host, as a remote > code execution attack. The only patched versions are 15.0.8 and 16.0.4, neither of which have been pushed to any of the FreeBSD package repos, nor are vulnerabilities for the affected versions reported by `pkg audit`, so ideally we’d be able to get both done soon as this RCE has been public (and much discussed) for several days now. Note that gitea (also available via FreeBSD ports and packages) addressed this same issue quite some time ago and is not vulnerable. Could someone please commit an entry to FreeBSD's VuXML and, hopefully, work on updating the affected ports? Upstream has acknowledged the security ramifications, but I am not aware of a CVE identifier being assigned yet, fwiw. [0]: https://codeberg.org/forgejo/forgejo/pulls/14300 Mahmoud Al-Qudsi NeoSmart Technologies