CVE-2026-27941Disclosure(openlit / openlit_software_development_kit)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch openlit openlit_software_development_kit systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openlit_software_development_kit

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-26); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
openlit_software_development_kit

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-26: 4Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1Mentions · 2026-03-06: 1Mentions · 2026-09-06: 2PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-09-06: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 102-2602-2703-0303-0609-06
Signal classification3 categories
Disclosure
666.7%
Patch
222.2%
Exploit
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure2Patch2
2026-02-271
Disclosure1
2026-03-031
Disclosure1
2026-03-061
Disclosure1
2026-09-062
Disclosure1Exploit1
Full discourse9 posts
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-5si8FXH [CRITICAL/PoC] Linked: CVE-2026-27941 gha-lab-6c3094af9e 🔗 https://exploitgrid.net/exploits/5b94e163-21a7-4b6b-980c-eb193c046cd1

    Post summary

    A critical PoC/ exploit for CVE‑2026‑27941 is publicly available via ExploitGrid, indicating a functional exploitation tool is shared.

    1000052
    40 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-27941 CVE-2026-31852 CVE-2026-56290 CVE-2026-7873 CVE-2023-42793 ..🧵👇

    Post summary

    A daily digest listing newly disclosed CVEs without additional details on exploitation or mitigation.

    1000049
    40 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27941 GitHub Actions Privilege Escalation in OpenLIT Before Version 1.37.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27941

    Post summary

    A privilege escalation vulnerability (CVE-2026-27941) affecting OpenLIT before version 1.37.1 has been disclosed, with no evidence of PoC, exploit, or patch details provided.

    0000137
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenLIT, CI/CD Remote Code Execution, #CVE-2026-27941 (CRITICAL) https://dailycve.com/openlit-ci-cd-remote-code-execution-cve-2026-27941-critical/

    Post summary

    A brief announcement of CVE-2026-27941 affecting OpenLIT CI/CD for remote code execution, linking to a dailycve.com resource but offering no further technical, exploit, or mitigation details.

    0000034
    164 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27941 (CVSS:9.9, CRITICAL) is Awaiting Analysis. OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open..https://nvd.nist.gov/vuln/detail/CVE-2026-27941 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-27941 is a critical vulnerability in OpenLIT’s GitHub Actions workflows, currently awaiting analysis, with no details on exploitation or patching.

    0000031
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical vulnerability (CVE-2026-27941) in `openlit` GitHub Actions workflows enables RCE and secret exposure via `pull_request_target` misuse. Review and update your #GitHubActions configurations. #SupplyChain #PythonSec https://www.pulsepatch.io/posts/cve-2026-27941-openlit-github-actions-rce

    Post summary

    A critical RCE vulnerability (CVE-2026-27941) in openlit GitHub Actions workflows has been disclosed, with technical details and a recommendation to update GitHub Actions configurations to mitigate the risk.

    0000052
    1 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27941 OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_… https://www.cve.org/CVERecord?id=CVE-2026-27941

    Post summary

    The CVE-2026-27941 issue in OpenLIT is addressed by upgrading to version 1.37.1; no PoC, exploit, or active exploitation is reported.

    00000120
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27941: CRITICAL] OpenLIT addressed a critical security vulnerability in GitHub Actions workflows prior to version 1.37.1, mitigating risks related to executing untrusted code from pull requests.#cve,CVE-2026-27941,#cybersecurity https://cvefind.com/CVE-2026-27941

    Post summary

    The post announces that OpenLIT has fixed a critical vulnerability in GitHub Actions workflows before version 1.37.1, mitigating risks of executing untrusted code from pull requests.

    0000044
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-27941 pertains to a security flaw in the open-source platform **OpenLIT**, specifically prior to version 1.37.1. The core issue involves the misuse of GitHub Actions workflows that utilize the `pull_request_target` event. These workflows, when triggered by pull requests from forked repositories, execute with elevated privileges and access to sensitive secrets, including API keys, database tokens, and cloud service account keys. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #Google https://cvetodo.com/cve/CVE-2026-27941

    Post summary

    The post discloses CVE-2026-27941, detailing how OpenLIT’s GitHub Actions misuse allows forked pull requests to run with elevated privileges and access sensitive secrets, but it does not provide a PoC, exploit, or patch information.

    0000046
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenlitopenlit_software_development_kit-python-

Explore more