Vulnerability Description
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, enabling RCE with write permissions. This vulnerability is fixed in 2.1.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/OWASP-BLT/BLT/security/advisories/GHSA-cgvj-qg2h-cqfh
- https://github.com/OWASP-BLT/BLT/security/advisories/GHSA-cgvj-qg2h-cqfh
FAQ
What is CVE-2026-42603?
CVE-2026-42603 is a vulnerability with a CVSS score of 8.8 (HIGH). OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_tar...
How severe is CVE-2026-42603?
CVE-2026-42603 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42603?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.