{"id":"CVE-2026-41249","summary":"CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration","details":"CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the pull request head (`ref: ${{ github.event.pull_request.head.ref }}`). Subsequently, it executes a script (`bin/console`) from this untrusted checkout. This allows any external attacker to achieve Remote Code Execution (RCE) on the GitHub Actions runner simply by submitting a malicious Pull Request. Also known as a \"Pwn Request\" vulnerability. As of time of publication, `pull_request_target` is still in the file.","aliases":["GHSA-q58j-g3f4-h26h"],"modified":"2026-08-04T11:51:20.722692760Z","published":"2026-06-04T19:26:46.043Z","database_specific":{"cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41249.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/coreshop/CoreShop/blob/5.1.0-beta.1/.github/workflows/static.yml#L14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41249.json"},{"type":"ADVISORY","url":"https://github.com/coreshop/CoreShop/security/advisories/GHSA-q58j-g3f4-h26h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41249"},{"type":"FIX","url":"https://github.com/coreshop/CoreShop/commit/cc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coreshop/coreshop","events":[{"introduced":"05bf7af946c919896d0807e4f0c7af37f446653b"},{"last_affected":"8911f81e18654647dc1ea7e110eb7a450b0c437c"}],"database_specific":{"extracted_events":[{"introduced":"5.0.1"},{"last_affected":"5.1.0-beta.1"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41249.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}