It can't be done without authenticating first, but there's nothing about RCE that says that it must be sent from unauthenticated connection.
You should be OK, but if attacker takes over your user (or any user in your forgejo instance) they can execute code on the host server - as you said yourself. In other words, it allows them to achieve remote code execution, so it's a RCE.