Skip to content
cyberMEDIUM2026-04-24 19:17 UTC

CVE-2026-41414 - Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml

CVE ID :CVE-2026-41414 Published : April 24, 2026, 7:17 p.m. | 40 minutes ago Description :Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with acce

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber