PatchSiren cyber security CVE debrief
CVE-2026-89094 Forgejo CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-10T21:17:53.160Z and has not been modified since then. This critical vulnerability in Forgejo, tracked as CVE-2026-89094, allows remote code execution via crafted template repositories. The vulnerability has a CVSS score of 9.9 and is considered critical. Defenders responsible for Forgejo installations, security teams assessing exposure to remote code execution, and administrators of systems using Forgejo should verify and apply remediation. The CVE record and NVD entry provide limited information about the vulnerability. Verification of Forgejo installations and application
- Vendor
- Forgejo
- Product
- Unknown
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Forgejo installations, security teams assessing exposure to remote code execution, and administrators of systems using Forgejo should verify and apply remediation.
Why it matters
CVE-2026-89094 is a critical vulnerability in Forgejo that allows remote code execution via crafted template repositories. Defenders should prioritize verification and remediation to prevent exploitation.
- Remote code execution via crafted template repositories requires immediate verification and remediation
- Exposure to remote code execution can lead to system compromise and data breaches
- Verification of Forgejo installations and application of vendor remediation are critical to preventing exploitation
Technical summary
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled. This vulnerability has a CVSS score of 9.9 and is considered critical. The vulnerability is caused by the mishandling of template expansion on files in .forgejo/template, which allows attackers to execute remote code. Defenders should prioritize verification of Forgejo installations and assess exposure to remote code execution via crafted template repositories. The official CVE Program record and NIST NVD
Defensive priority
Defenders should prioritize verification of Forgejo installations and assess exposure to remote code execution via crafted template repositories.
Recommended defensive actions
- Verify Forgejo installations for exposure to remote code execution via crafted template repositories
- Assess and apply vendor remediation for Forgejo versions prior to 16.0.4
- Monitor for suspicious activity related to template repository expansion
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 9.9 and a description of remote code execution via crafted template repositories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89094 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89094
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89094 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89094
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://codeberg.org/forgejo/forgejo/milestone/139655
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.