CVE-2026-24480Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commit checks" that, before commit 76a693cd91650f9b4e83edac525e5e4f90d954e9, was vulnerable to remote code execution and repository compromise because it used the `pull_request_target` trigger and then checked out and executed untrusted pull request code in a privileged context. Workflows triggered by `pull_request_target` ran with the base repository's credentials and access to secrets. If these workflows then checked out and executed code from the head of an external pull request (which could have been attacker controlled), the attacker could have executed arbitrary commands with elevated privileges. This insecure pattern has been documented as a security risk by GitHub and security researchers. Commit 76a693cd91650f9b4e83edac525e5e4f90d954e9 removed the vulnerable code.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-01-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-27: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 101-2703-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    A new critical security advisory for QGIS on #Fedora 42 (CVE-2026-24480) requires immediate attention. Read more: 👉 https://tinyurl.com/4yue3wu5 #Security https://t.co/KahSI1IlzX

    Post summary

    A new critical advisory for QGIS on Fedora 42 (CVE-2026-24480) has been issued, urging immediate attention. The tweet does not provide PoC, exploit details, or patch information.

    0000063
    1.4K followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-24480 blottlägger allvarliga sårbarheter i QGIS GitHub Actions. En tidigare osäker användning av "pull_request_target" kan leda till fjärrkodexekvering med privilegierad åtkomst. Viktigt att uppdatera skydd och granska kod! #säkerhet #cybersäkerhet #CVE

    Post summary

    CVE-2026-24480 exposes critical remote‑code‑execution flaws in QGIS GitHub Actions through unsafe pull_request_target usage, urging developers to apply updates and review security controls.

    0000071
    7 followersView on X

Explore more