Vulnerability Report

CVE-2026-41414

RCE

Title: Skim Remote Code Execution via GitHub Actions workflow

RCE

Proof Of Concept

PoC Available for CVE-2026-41414

CWE Category CWE-94
Published Date Apr 24, 2026
Modified Date May 01, 2026
Exploit Status Available
Score 7.4 CVSS v3.1
Exploit Probability (EPSS)
0.44%

Vulnerability Summary

CVE-2026-41414: Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.

CVSS v3.1
Source Entity [email protected]
Severity HIGH
7.4
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
REQUIRED
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-41414 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/pvharmo2/gha-lab-456dd8a245
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction REQUIRED
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Affected Stack

No specific products linked.