OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, enabling RCE with write permissions. This vulnerability is fixed in 2.1.2.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 11 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owasp-blt
Owasp-blt blt |
|
| Vendors & Products |
Owasp-blt
Owasp-blt blt |
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, enabling RCE with write permissions. This vulnerability is fixed in 2.1.2. | |
| Title | OWASP BLT: pre-commit-fix.yaml executes untrusted fork code via pull_request_target | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T17:27:55.699Z
Reserved: 2026-04-29T00:31:15.725Z
Link: CVE-2026-42603
No data.
Status : Received
Published: 2026-05-11T17:16:33.410
Modified: 2026-05-11T17:16:33.410
Link: CVE-2026-42603
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:30:15Z