CVE-2026-41414

Source
https://cve.org/CVERecord?id=CVE-2026-41414
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41414.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41414
Aliases
  • GHSA-9g93-rxr5-xhqw
Downstream
Related
Published
2026-04-24T18:32:36.283Z
Modified
2026-07-15T01:49:18.245114362Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N CVSS Calculator
Summary
Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml
Details

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIMRSBOTPRIVATEKEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41414.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "bf63404ad51985b00ed304690ba9d477860a5a75"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/skim-rs/skim

Affected ranges

Type
GIT
Repo
https://github.com/skim-rs/skim
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:skim-rs:skim:*:*:*:*:*:rust:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.6.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

common-v0.*
common-v0.1.0
common-v0.1.1
common-v0.1.2
common-v0.2.0
tuikit-v0.*
tuikit-v0.6.0
tuikit-v0.6.1
tuikit-v0.6.2
tuikit-v0.6.3
tuikit-v0.6.4
tuikit-v0.6.5
tuikit-v0.6.6
v0.*
v0.1-alpha
v0.1.1-rc2
v0.1.1-rc3
v0.1.2
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.11.0
v0.11.1
v0.11.10
v0.11.11
v0.11.12
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.11.7
v0.11.8
v0.11.9
v0.12.0
v0.13.0
v0.14.3
v0.15.0
v0.15.1
v0.15.2
v0.15.3
v0.15.4
v0.15.5
v0.15.6
v0.15.7
v0.16.0
v0.16.1
v0.16.2
v0.17.0
v0.17.1
v0.17.2
v0.17.3
v0.18.0
v0.19.0
v0.2.1-beta.1
v0.2.1-beta.2
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.20.5
v0.3.0
v0.3.1
v0.3.2
v0.4.0
v0.5.0
v0.5.1
v0.5.3
v0.5.4
v0.5.5
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.8.0
v0.8.2
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v1.*
v1.0.0
v1.0.0-pre1
v1.0.0-pre10
v1.0.0-pre11
v1.0.0-pre2
v1.0.0-pre3
v1.0.0-pre4
v1.0.0-pre5
v1.0.0-pre6
v1.0.0-pre7
v1.0.0-pre8
v1.0.0-pre9
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.10.0
v1.11.0
v1.11.1
v1.11.2
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.9.0
v1.9.1
v2.*
v2.0.0
v2.0.1
v2.0.2
v3.*
v3.0.0
v3.0.1
v3.1.0
v3.1.1
v3.2.0
v3.3.0
v3.4.0
v3.5.0
v3.6.0
v3.6.1
v3.6.2
v3.7.0
v4.*
v4.0.0
v4.0.1
v4.1.0
v4.2.0
v4.3.0
v4.4.0
v4.5.0
v4.5.1
v4.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41414.json"