CVE-2026-22869
EUVD-2026-241413.01.2026, 21:15
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| eigent | eigent | 𝑥 < 0.0.78 |
𝑥
= Vulnerable software versions