Forgejo publishes 16.0.4 release notes for critical RCE in 16.0.3 and earlier
Forgejo versions up to and including 16.0.3 carry a critical remote code execution vulnerability, according to a Hacker News submission that links to the project's release notes for version 16.0.4. The item was posted under the title "Forgejo <=16.0.3 Critical RCE" and pointed readers at the file 16.0.4.md in the release-notes-published directory of the Forgejo repository on Codeberg. When the item was captured it had drawn 33 points and 9 comments.
The linked artifact is a patch-level release note on the 16.0 line, the version that follows 16.0.3. Forgejo publishes release notes as versioned markdown files in that repository directory, so the pointer hands readers the primary document instead of a summary. The submission itself carries no explanatory text beyond the title and the URL. That leaves the release note file as the source of record for what the update changes and what operators are expected to do about it.
Most of the technical detail a critical RCE notice normally carries is absent from the material available here. There is no CVE identifier in the item, and no severity score. No description of the vulnerable code path appears, nor any statement about whether exploitation requires authentication, a specific configuration, or a particular deployment shape such as a publicly reachable instance. The item also says nothing about exploitation in the wild or how the project learned of the flaw.
The sourcing is thin enough that the picture stays incomplete. The submission is a link and a title, and the full text of 16.0.4.md could not be retrieved during this reporting pass, so the claims that the vulnerability is critical and that it reaches every release through 16.0.3 rest on the submission title alone. The affected range is stated as an upper bound rather than a list of maintained branches, which leaves open whether the 15.0 long-term-support line has a matching backport or remains exposed.
One mismatch is worth stating plainly. The item appears under a label that references local LLMs, while its subject is a Forgejo security release. The labeling does not change the underlying pointer, which goes to Forgejo's own release-notes file, but it means the item surfaced to an audience that may not be tracking forge security releases. The 9 comments attached to the submission are not reproduced in the material available here, so any technical discussion that accompanied the post is unaccounted for.
For administrators, the operative facts are narrow: a fix is associated with 16.0.4, and 16.0.3 and everything below it is named as affected. It remains unknown whether 16.0.4 has actually been tagged and is available to install, when the notes were published, whether other maintained branches are covered, and what the project has said about severity and exposure. Those questions have answers in the release note and in the project's security announcements, and neither document is summarized in the lead item provided.
A critical remote code execution flaw in a widely self-hosted forge means every administrator running 16.0.3 or earlier needs the patch details, and the lead item supplied here gives them a pointer to the release notes without any of the technical specifics needed to judge exposure.