V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-27941
CVE
Critical

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub reposi…

CVSS
9.9
Critical
EPSS
0.00
p31
Published
2026-01-01
Updated
2026-01-01
Description

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.

Tags · CWE
CWE-829
CAPEC-175
CAPEC-201
CAPEC-228
CAPEC-251
CAPEC-252
CAPEC-253
CAPEC-263
CAPEC-538
CAPEC-549
CAPEC-640
CAPEC-660
CAPEC-695
CAPEC-698
Affected products
Openlit_software_development_kit 1.36.2–1.37.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p31
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-251 · CWE-829
└ via CAPEC-698 · CWE-829
└ via CAPEC-698 · CWE-829
└ via CAPEC-640 · CWE-829
└ via CAPEC-640 · CWE-829
└ via CAPEC-640 · CWE-829
└ via CAPEC-640 · CWE-829
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
openlit_software_development_kit*Tracked