{"id":"CVE-2026-22869","summary":"Eigent Allows Arbitrary Code Execution via pull_request_target CI Workflow","details":"Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.","aliases":["GHSA-gvh4-93cq-5xxp"],"modified":"2026-08-12T03:51:48.829178727Z","published":"2026-01-13T20:38:42.662Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5"}]}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22869.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22869.json"},{"type":"ADVISORY","url":"https://github.com/eigent-ai/eigent/security/advisories/GHSA-gvh4-93cq-5xxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22869"},{"type":"FIX","url":"https://github.com/eigent-ai/eigent/commit/bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5"},{"type":"FIX","url":"https://github.com/eigent-ai/eigent/pull/836"},{"type":"FIX","url":"https://github.com/eigent-ai/eigent/pull/837"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eigent-ai/eigent","events":[{"introduced":"0"},{"fixed":"a96c08802542ad9dade1102dac276f3255ebe77a"},{"fixed":"bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:eigent:eigent:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.0.78"}]}}],"versions":["v0.0.77","v0.0.75","v0.0.74","v0.0.73","v0.0.72","v0.0.71","v0.0.70","v0.0.68","v0.0.67","v0.0.66","v0.0.63","v0.0.65","v0.0.62","v0.0.61","v0.0.60","v0.0.58","v0.0.57","v0.0.53-test","v0.0.55","v0.0.54","v0.0.53","v0.0.52","v0.0.51"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22869.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}