Open Source AI Engineering Platform Vulnerability in OpenLIT
CVE-2026-27941
10CRITICAL
What is CVE-2026-27941?
OpenLIT, an open-source platform for AI engineering, contains a vulnerability in its GitHub Actions workflows prior to version 1.37.1. These workflows utilize the pull_request_target event and allow for the execution of untrusted code from forked pull requests. This could potentially grant attackers the ability to operate with the security context of the base repository, exposing sensitive information, including API keys, database credentials, and service account secrets. Users are advised to upgrade to version 1.37.1, which addresses this vulnerability.
Affected Version(s)
openlit < 1.37.1
