Remote Code Execution Vulnerability in CoreShop eCommerce Solution by Pimcore
CVE-2026-41249

8.2HIGH

Key Information:

Vendor

Coreshop

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-41249?

CoreShop, an eCommerce solution developed by Pimcore, exhibits a vulnerability in its GitHub Actions workflow due to the use of the 'pull_request_target' trigger. This vulnerability allows external attackers to execute unverified code by submitting a malicious Pull Request. The workflow checks out code from the pull request head, enabling potential remote code execution (RCE) on the GitHub Actions runner. The design flaw poses significant risk, making it susceptible to exploitation if not addressed promptly. Users are advised to review the affected versions and secure their implementations against this threat.

Affected Version(s)

CoreShop >= 5.0.1, <= 5.1.0-beta.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.