Remote Code Execution Flaw in OWASP BLT by Attackers' Fork Access
CVE-2026-42603
8.8HIGH
What is CVE-2026-42603?
OWASP BLT, a platform for QA testing and vulnerability disclosures, has a security flaw where the .github/workflows/pre-commit-fix.yaml file utilizes the pull_request_target trigger inappropriately. This configuration allows execution of code directly from a malicious user’s fork, leading to potential remote code execution with elevated permissions. The vulnerability has been addressed in version 2.1.2, underscoring the importance of keeping software up-to-date to mitigate risks.
Affected Version(s)
BLT < 2.1.2
