Remote Code Execution Flaw in OWASP BLT by Attackers' Fork Access
CVE-2026-42603

8.8HIGH

Key Information:

Vendor

Owasp-blt

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-42603?

OWASP BLT, a platform for QA testing and vulnerability disclosures, has a security flaw where the .github/workflows/pre-commit-fix.yaml file utilizes the pull_request_target trigger inappropriately. This configuration allows execution of code directly from a malicious user’s fork, leading to potential remote code execution with elevated permissions. The vulnerability has been addressed in version 2.1.2, underscoring the importance of keeping software up-to-date to mitigate risks.

Affected Version(s)

BLT < 2.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.