VYPR
Critical severity9.9NVD Advisory· Published Sep 10, 2026

CVE-2026-89094

CVE-2026-89094

Description

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Affected products

2
  • Forgejo/Forgejoinferred2 versions
    <16.0.4+ 1 more
    • (no CPE)range: <16.0.4
    • (no CPE)range: <16.0.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.