Untriaged
Permalink
CVE-2026-44590
9.3 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the GITHUB_TOKEN by opening a pull request. No approval, review, or merge is required. This vulnerability is fixed in 0.16.1.
References
Affected products
sherlock
- ==< 0.16.1
Matching in nixpkgs
pkgs.sherlock
Hunt down social media accounts by username across social networks
pkgs.sherlock-launcher
Lightweight and efficient application launcher for Wayland built with Rust and GTK4
Package maintainers
-
@magnetophon Bart Brouns <bart@magnetophon.nl>
-
@applePrincess Lein Matsumaru <appleprincess@appleprincess.io>
-
@agvantibo-again Savchenko Dmitriy <apicalium@gmail.com>