{"id":"PYSEC-2026-2246","details":"OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.","aliases":["CVE-2026-27941","GHSA-9jgv-x8cq-296q"],"modified":"2026-07-13T07:15:39.568243055Z","published":"2026-02-26T02:16:22.160Z","references":[{"type":"FIX","url":"https://github.com/openlit/openlit/commit/4a62039a1659d6cbb8913172693f587b5fc2546c"},{"type":"EVIDENCE","url":"https://github.com/openlit/openlit/security/advisories/GHSA-9jgv-x8cq-296q"}],"affected":[{"package":{"name":"openlit","ecosystem":"PyPI","purl":"pkg:pypi/openlit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.36.2"},{"fixed":"1.37.1"}]}],"versions":["1.36.2","1.36.3","1.36.6","1.36.7","1.36.8","1.36.9","1.37.0"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/openlit/PYSEC-2026-2246.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}