{"id":"CVE-2026-41249","aliases":["GHSA-q58j-g3f4-h26h"],"url":"https://o3.security/vulnerability/CVE-2026-41249","summary":"CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration","details":"### Summary\n\nThe GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the pull request head (`ref: ${{ github.event.pull_request.head.ref }}`). Subsequently, it executes a script (`bin/console`) from this untrusted checkout.\nThis allows any external attacker to achieve Remote Code Execution (RCE) on the GitHub Actions runner simply by submitting a malicious Pull Request. Also known as a \"Pwn Request\" vulnerability.\n\n**Steps to Reproduce:**\n1. Fork the target repository.\n2. In the forked repository, modify a file that satisfies the `paths` condition (e.g., `src/dummy.php` or `composer.json`) to trigger the workflow.\n3. Modify the `bin/console` file (which is executed in the workflow steps) with the following malicious payload:\n```bash\n#!/bin/bash\necho \"=== PWNED ===\"\necho \"whoami:\"\nwhoami\n```\n4. Commit the changes and open a Pull Request against the `5.0` or `next` branch of the base repository.\n5. The `Static Tests` workflow will trigger automatically. Navigate to the Actions tab and inspect the logs for the `Validate YAML` (or any step executing `bin/console`).\n6. You will see the output of `whoami` (typically `runner`), proving that the arbitrary code was successfully executed in the runner's context.\n\n<img width=\"490\" height=\"87\" alt=\"スクリーンショット 2026-04-14 11 14 56\" src=\"https://github.com/user-attachments/assets/94276033-b989-46dc-b4a1-3dafa1603235\" />\n\n\n**Impact:**\nBecause `pull_request_target` runs in the context of the base repository, the runner has access to repository secrets (e.g., `PIMCORE_SECRET`, `PIMCORE_PRODUCT_KEY`) loaded in the environment. An attacker can exfiltrate these secrets, modify repository contents (if the token has write permissions), or abuse the runner's computing resources.\n\n**Recommended Mitigation:**\nDo not checkout untrusted PR code (`head.ref`) when using `pull_request_target` if the code will be built or executed.\nConsider adopting a separated architecture using the `workflow_run` event:\n1. Use the `pull_request` event to safely run the build/tests in an unprivileged sandbox and upload artifacts.\n2. Use the `workflow_run` event (which is privileged) to download the artifacts and perform actions requiring secrets.","published":"2026-06-04T19:26:46.043Z","modified":"2026-08-12T03:51:39.160426659Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00433,"percentile":0.36082,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"coreshop/core-shop","fixedVersion":null}],"fix":{"url":"https://github.com/coreshop/CoreShop/commit/cc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4","label":"coreshop/CoreShop@cc1e3f5"},"references":[{"type":"WEB","url":"https://github.com/coreshop/CoreShop/blob/5.1.0-beta.1/.github/workflows/static.yml#L14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41249.json"},{"type":"ADVISORY","url":"https://github.com/coreshop/CoreShop/security/advisories/GHSA-q58j-g3f4-h26h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41249"},{"type":"FIX","url":"https://github.com/coreshop/CoreShop/commit/cc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4"},{"type":"PACKAGE","url":"https://github.com/coreshop/CoreShop"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:39.160426659Z"}}