CVE-2026-27941: Openlit Software Development Kit

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 contains a fix.

Affected products

  • Openlit Openlit Software Development Kit: from 1.36.2, before 1.37.1 (fixed in 1.37.1)

Published 2026-02-26. Last modified 2026-06-17.