CVE-2026-42603 | OWASP-BLT up to 2.1.1 pre-commit-fix.yaml pull_request_target code injection (GHSA-cgvj-qg2h-cqfh)
A vulnerability described as critical has been identified in OWASP-BLT BLT up to 2.1.1. Affected by this issue is the function pull_request_target of the file github/workflows/pre-commit-fix.yaml. The manipulation results in code injection.
This vulnerability is reported as CVE-2026-42603. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.