CVE-2026-27941: OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions Workflows
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the pullrequesttarget event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged GITHUBTOKEN and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27941?
CVE-2026-27941 is classified as a critical vulnerability due to its potential for remote code execution and secret exposure.
How do I fix CVE-2026-27941?
To mitigate CVE-2026-27941, update OpenLIT to version 1.37.1 or later where the vulnerability has been addressed.
Which versions of OpenLIT are affected by CVE-2026-27941?
OpenLIT versions prior to 1.37.1 are affected by CVE-2026-27941.
What kind of attacks can CVE-2026-27941 enable?
CVE-2026-27941 can enable remote code execution and could lead to unauthorized access to sensitive information.
Are there any specific GitHub Actions workflows at risk due to CVE-2026-27941?
Yes, several GitHub Actions workflows in OpenLIT's repository are vulnerable due to the misuse of the `pull_request_target` event.