PT-2026-22081 · Openlist · Openlist

·

CVE-2026-27941

·

Published

2026-02-26

·

Updated

2026-03-03

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenLIT versions prior to 1.37.1
Description OpenLIT, an open source AI engineering platform, has an issue in GitHub Actions workflows prior to version 1.37.1. These workflows use the pull request target event and execute untrusted code from forked pull requests with the security context of the base repository. This includes a write-privileged GITHUB TOKEN and access to sensitive secrets such as API keys, database/vector store tokens, and a Google Cloud service account key. The pull request target event allows execution of code from potentially malicious pull requests.
Recommendations Update OpenLIT to version 1.37.1 or later.

Exploit

Fix

LPE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27941
GHSA-9JGV-X8CQ-296Q
PYSEC-2026-2246

Affected Products

Openlist