{"id":"CVE-2026-41249","aliases":["GHSA-q58j-g3f4-h26h"],"url":"https://o3.security/vulnerability/CVE-2026-41249","summary":"CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration","details":"CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the pull request head (`ref: ${{ github.event.pull_request.head.ref }}`). Subsequently, it executes a script (`bin/console`) from this untrusted checkout. This allows any external attacker to achieve Remote Code Execution (RCE) on the GitHub Actions runner simply by submitting a malicious Pull Request. Also known as a \"Pwn Request\" vulnerability. As of time of publication, `pull_request_target` is still in the file.","published":"2026-06-04T19:26:46.043Z","modified":"2026-08-07T11:51:03.237257513Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00433,"percentile":0.35658,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"coreshop/core-shop","fixedVersion":null}],"fix":{"url":"https://github.com/coreshop/CoreShop/commit/cc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4","label":"coreshop/CoreShop@cc1e3f5"},"references":[{"type":"WEB","url":"https://github.com/coreshop/CoreShop/blob/5.1.0-beta.1/.github/workflows/static.yml#L14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41249.json"},{"type":"ADVISORY","url":"https://github.com/coreshop/CoreShop/security/advisories/GHSA-q58j-g3f4-h26h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41249"},{"type":"FIX","url":"https://github.com/coreshop/CoreShop/commit/cc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:03.237257513Z"}}