Remote Code Execution Vulnerability in CoreShop eCommerce Solution by Pimcore
CVE-2026-41249
8.2HIGH
What is CVE-2026-41249?
CoreShop, an eCommerce solution developed by Pimcore, exhibits a vulnerability in its GitHub Actions workflow due to the use of the 'pull_request_target' trigger. This vulnerability allows external attackers to execute unverified code by submitting a malicious Pull Request. The workflow checks out code from the pull request head, enabling potential remote code execution (RCE) on the GitHub Actions runner. The design flaw poses significant risk, making it susceptible to exploitation if not addressed promptly. Users are advised to review the affected versions and secure their implementations against this threat.
Affected Version(s)
CoreShop >= 5.0.1, <= 5.1.0-beta.1
