Forgejo v1.21.11-0 was released on April 18, 2024, addressing two security vulnerabilities affecting registered users. The more critical flaw is a privilege escalation via git push options, allowing any registered user to change the visibility of any repository they can see, regardless of their access level. The second is an XSS vulnerability where improperly guarded repository content rendering allowed unsandboxed client-side scripts to run from the forge's domain. All Forgejo installations are strongly urged to upgrade immediately.
Table of contents
Recommended ActionPrivilege escalation through git push optionsCross-site scripting (XSS) vulnerabilityContribute to Forgejo4 Impressions