Forgejo has released critical security updates for versions 16.0.4 and 15.0.8, addressing a remote code execution (RCE) flaw that could lead to full server compromise. Administrators of self-hosted instances must apply these patches immediately, as no workarounds exist.
As reported by LWN.net, the emergency updates remediate two security vulnerabilities. The most severe is a critical RCE bug that, if exploited, would allow an attacker to execute arbitrary commands on the host system with the privileges of the Forgejo service. This poses a direct risk of server takeover, threatening platforms that often store sensitive source code, private projects, and development credentials.
Forgejo is a community-driven, open-source fork of Gitea, providing self-hosted Git repository hosting and collaborative development tools. The dual-branch patching strategy—covering both the current 16.x series and the older 15.x line—allows administrators to secure systems without forcing a major version upgrade, accommodating diverse operational cycles.
The project confirms that updating is the sole mitigation. Administrators should consult the release notes published on Forgejo's repository for each version. This incident underscores a core principle of self-hosted infrastructure: while it offers control and data sovereignty, it places the full burden of security monitoring, risk assessment, and timely patching on the hosting organization.
Forgejo 已針對 16.0.4 及 15.0.8 版本發佈重要安全更新,解決一個可能導致伺服器被完全控制的遠端程式碼執行(RCE)漏洞。自架設實例的管理員必須立即套用這些修補程式,因目前並無任何解決方法。
據 LWN.net 報導,此次緊急更新修補了兩項安全漏洞。最嚴重的是一項關鍵 RCE 錯誤,若被利用,將允許攻擊者以 Forgejo 服務的權限,在主機系統上執行任意指令。這對伺服器構成直接被接管的風險,威脅到通常儲存敏感源碼、私人專案及開發憑證的平台。
Forgejo 是一個由社群主導、源自 Gitea 的開源分支,提供自架設的 Git 儲存庫託管及協作開發工具。此次覆蓋現行 16.x 系列及舊版 15.x 系列的雙分支修補策略,讓管理員無需強制進行主版本升級即可加強系統安全,以配合不同的運維週期。
該專案確認更新是唯一的緩解措施。管理員應查閱 Forgejo 儲存庫中針對每個版本發佈的更新說明。此事件突顯了自架設基礎設施的一個核心原則:雖然它提供了控制權及數據主權,但同時也將安全監控、風險評估及及時修補的全部責任,交託給託管組織。
