logoalt Hacker News

n3mes1stoday at 9:44 AM0 repliesview on HN

I'm working on a tool to reproduce stuff like this exactly.

Yep this is an RCE with the forgejo user on the host.

https://www.pruva.dev/reproductions/REPRO-2026-00345 for details.

you can even start your version of the repro using github codespaces

========================================

REPRO-2026-00345

========================================

Title: Forgejo <16.0.4 RCE via crafted template repository (.forgejo/template expansion recreates .git folder adopted by git init)

Severity: CRITICAL

CVE: CVE-2026-89094

========================================

[pruva] Working directory: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345

[pruva] Found script artifact: bundle/repro/reproduction_steps.sh

[pruva] Downloaded 4 repro artifact(s), script: 324 lines

[pruva] ==========================================

[pruva] WARNING: This will execute code that

[pruva] exploits a real vulnerability.

[pruva] ==========================================

[pruva] Auto-confirming in sandbox environment...

[pruva] Running reproduction script...

--- REPRODUCTION OUTPUT ---

[09:39:29] ensuring container images are present

[09:39:42] vulnerable image digest: sha256:214f4ae63ee78be1e445e58573c88dc7215e72091210852e0df94eaac1a25685

[09:39:42] fixed image digest: sha256:a263a1298e89e0bdf019005ce1927e9aadaa8f1bd2a94a3e66ad94e2a89e19ce

[09:39:42] [vuln-1] starting container (codeberg.org/forgejo/forgejo:16.0.3-rootless)

[09:39:52] [vuln-1] service healthy on 127.0.0.1:4011

[09:39:53] [vuln-1] admin user + token ready

[09:39:55] [vuln-1] malicious template pushed

[09:40:03] [vuln-1] generate API returned 201

[09:40:15] [vuln-1] marker=**** hook_id=**** hostdata=**** readme_ok=**** gen=201

[09:40:15] [vuln-2] starting container (codeberg.org/forgejo/forgejo:16.0.3-rootless)

[09:40:25] [vuln-2] service healthy on 127.0.0.1:4012

[09:40:26] [vuln-2] admin user + token ready

[09:40:28] [vuln-2] malicious template pushed

[09:40:32] [vuln-2] generate API returned 201

[09:40:36] [vuln-2] marker=**** hook_id=**** hostdata=**** readme_ok=**** gen=201

[09:40:36] [fixed-1] starting container (codeberg.org/forgejo/forgejo:16.0.4-rootless)

[09:40:40] [fixed-1] service healthy on 127.0.0.1:4111

[09:40:40] [fixed-1] admin user + token ready

[09:40:41] [fixed-1] malicious template pushed

[09:40:46] [fixed-1] generate API returned 201

[09:40:50] [fixed-1] marker=false hook_id=false hostdata=false readme_ok=**** gen=201

[09:40:50] [fixed-2] starting container (codeberg.org/forgejo/forgejo:16.0.4-rootless)

[09:40:52] [fixed-2] service healthy on 127.0.0.1:4112

[09:40:53] [fixed-2] admin user + token ready

[09:40:54] [fixed-2] malicious template pushed

[09:40:58] [fixed-2] generate API returned 201

[09:41:02] [fixed-2] marker=false hook_id=false hostdata=false readme_ok=**** gen=201

[09:41:02] vuln markers: **** / **** ; hook-id: **** / **** ; hostdata: **** / **** ; gen: 201 / 201

[09:41:02] fixed markers: false / false ; readme-ok: **** / **** ; gen: 201 / 201 runtime_manifest.json written with 44 proof artifacts

[09:41:02] VERDICT: CONFIRMED - remote code execution reproduced on Forgejo 16.0.3 via crafted template repository; fixed 16.0.4 unaffected

--- END REPRODUCTION OUTPUT ---

[pruva] ==========================================

[pruva] VERIFICATION SUCCESSFUL

[pruva] Duration: 93s

[pruva] ==========================================

[pruva] Logs: /workspaces/pruva-sandbox/pruva-results/REPRO- 2026-00345/logs/ - fixed-1 - fixed-2 - reproduction_steps.log - vuln-1 - vuln-2

[pruva] Results saved to: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345

[pruva] Keeping work directory: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345 Outcome: success User: vscode WorkspaceFolder: /workspaces/pruva-sandbox