CVE 8.9 HIGH

Eigent Allows Arbitrary Code Execution via pull_request_target CI Workflow_CVE-2026-22869

8.9 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.

AI Analysis

Arbitrary code execution via pull_request_target CI workflow

Basic Information

ID CVE-2026-22869
Source GitHub_M
Published Jan 13, 2026 at 20:38

Affected Product

Vendor eigent-ai
Product eigent
Version < bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5
Affected Versions eigent-ai eigent < bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5

CWE Classification

AI Assessment

AI Score 8.9 / 10
AI Severity High
Vendor eigent-ai
Product eigent
Version bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.