Open Source AI Engineering Platform Vulnerability in OpenLIT
CVE-2026-27941

10CRITICAL

Key Information:

Vendor

Openlit

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-27941?

OpenLIT, an open-source platform for AI engineering, contains a vulnerability in its GitHub Actions workflows prior to version 1.37.1. These workflows utilize the pull_request_target event and allow for the execution of untrusted code from forked pull requests. This could potentially grant attackers the ability to operate with the security context of the base repository, exposing sensitive information, including API keys, database credentials, and service account secrets. Users are advised to upgrade to version 1.37.1, which addresses this vulnerability.

Affected Version(s)

openlit < 1.37.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.