Posted by weierstass 18 hours ago
0. https://codeberg.org/forgejo/forgejo/src/branch/forgejo/rele...
It would take a boatload of such events to equal the opex of GitHub hosting. That’s not an excuse to run amok, but it’s far from tipping the scales in GitHub’s cost favor.
It can't be done without authenticating first, but there's nothing about RCE that says that it must be sent from unauthenticated connection.
You should be OK, but if attacker takes over your user (or any user in your forgejo instance) they can execute code on the host server - as you said yourself. In other words, it allows them to achieve remote code execution, so it's a RCE.