Forgejo, an increasingly adopted open-source Git platform (now used by Fedora), contains multiple critical security vulnerabilities including SSRF, authentication flaws, and remote code execution chains that can be exploited under certain configurations, posing significant risk to organizations relying on this software for code management and collaboration. The security researcher has demonstrated a working RCE exploit and is using "carrot disclosure" to incentivize Forgejo maintainers to conduct comprehensive security remediation rather than patch individual vulnerabilities, effectively creating a decision point for the vendor between conducting a holistic security audit or facing user attrition. This disclosure highlights the importance of vetting open-source infrastructure tools and the potential consequences of deploying software with immature security postures in critical development environments.
Forgejo, an increasingly adopted open-source Git platform (now used by Fedora), contains multiple critical security vulnerabilities including SSRF, authentication flaws, and remote code execution chains that can be exploited under certain configurations, posing significant risk to organizations relying on this software for code management and collaboration. The security researcher has demonstrated a working RCE exploit and is using "carrot disclosure" to incentivize Forgejo maintainers to conduct comprehensive security remediation rather than patch individual vulnerabilities, effectively creating a decision point for the vendor between conducting a holistic security audit or facing user attrition. This disclosure highlights the importance of vetting open-source infrastructure tools and the potential consequences of deploying software with immature security postures in critical development environments.