Vulnerability Report

CVE-2026-27941

Title: Untrusted code execution in OpenLIT GitHub Actions workflows

Other

Proof Of Concept

PoC Available for CVE-2026-27941

CWE Category CWE-829
Published Date Feb 26, 2026
Modified Date Mar 06, 2026
Exploit Status Available
Score 9.9 CVSS v3.1
Exploit Probability (EPSS)
0.57%

Vulnerability Summary

CVE-2026-27941: OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.

CVSS v3.1
Source Entity [email protected]
Severity CRITICAL
9.9
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-27941 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/pvharmo2/gha-lab-6c3094af9e
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Stack

No specific products linked.