- Sources: release notes, discussion
- Summary: The release notes state that generating a repository from a template clones the template, removes the
.git folder, expands variables in the files listed in .forgejo/template, then initializes a new git repository, and that variable expansion could be misused to create a new .git folder that git adopts during initialization, letting a malicious template read arbitrary data from the Forgejo host and execute arbitrary processes on it. The fix removes any .git folder after expansion and before initialization, and the release notes name neither an affected version range nor a CVE for this issue. The same release fixes an allow-maintainer-edit control that ignored API-specific restrictions, so a repo-scoped access token could modify branches outside its permission, and draft release attachments that were readable by read-only and unauthenticated callers, the class Gitea fixed as CVE-2026-27660. - Why it matters: The precondition is only that someone generates a repository from an attacker-controlled template, which is an ordinary action a self-hosted forge invites any user to take.
- Follow-up: Whether a CVE is assigned to the template execution issue.
send feedback on this story