Security Advisory
CVE-2026-89094
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.