HarborGuard / CVE
Back to search
HIGHCVE-2026-22869Published Modified CNA GitHub_M

CVE-2026-22869: Eigent Allows Arbitrary Code Execution via pull_request_target CI Workflow

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.

Metrics

CVSS v4.0
8.9
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • eigent-ai / eigent
    < bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P