CVE-2026-44590

NameCVE-2026-44590
DescriptionSherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the GITHUB_TOKEN by opening a pull request. No approval, review, or merge is required. This vulnerability is fixed in 0.16.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Only affects the GitHub Actions workflow for the src:sherlock upstream project
https://github.com/sherlock-project/sherlock/security/advisories/GHSA-v6wr-ccr4-x8g9

Search for package or bug name: Reporting problems