PT-2026-22081 · Openlist · Openlist

Nilsreichardt

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

·

CVE-2026-27941

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenLIT versions prior to 1.37.1
Description OpenLIT, an open source AI engineering platform, has an issue in GitHub Actions workflows prior to version 1.37.1. These workflows use the pull request target event and execute untrusted code from forked pull requests with the security context of the base repository. This includes a write-privileged GITHUB TOKEN and access to sensitive secrets such as API keys, database/vector store tokens, and a Google Cloud service account key. The pull request target event allows execution of code from potentially malicious pull requests.
Recommendations Update OpenLIT to version 1.37.1 or later.

Exploit

Correção

LPE

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27941
GHSA-9JGV-X8CQ-296Q

Produtos afetados

Openlist