CVE-2026-89094
EUVD-2026-7573210.09.2026, 21:17
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| forgejo | forgejo | 16.0.0 ≤ 𝑥 < 16.0.4 | CNA |
| forgejo | forgejo | 𝑥 < 15.0.8 | CNA |