DEBIAN-CVE-2026-41414

Source
https://security-tracker.debian.org/tracker/CVE-2026-41414
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41414.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-41414
Upstream
Withdrawn
2026-05-07T20:01:46Z
Published
2026-04-24T19:17:13Z
Modified
2026-05-07T20:01:46Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.

References

Affected packages

Debian:14 / skim

Package

Name
skim
Purl
pkg:deb/debian/skim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.20.5+ds-1
0.20.5+ds-2
0.20.5+ds-3
1.*
1.4.3-1
1.4.3-1.1
1.4.4-1
1.4.4-2
1.4.5-1
1.4.5-2
1.4.5-3
1.4.5-4
1.4.5-4.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41414.json"