Unrated severityOSV Advisory· Published Jan 13, 2026· Updated Jan 14, 2026
Eigent Allows Arbitrary Code Execution via pull_request_target CI Workflow
CVE-2026-22869
Description
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/eigent-ai/eigent/commit/bf02500bbbab0f01cd0ed8e6dc21fe5683d6bfb5mitrex_refsource_MISC
- github.com/eigent-ai/eigent/pull/836mitrex_refsource_MISC
- github.com/eigent-ai/eigent/pull/837mitrex_refsource_MISC
- github.com/eigent-ai/eigent/security/advisories/GHSA-gvh4-93cq-5xxpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.