Vulnerability Details CVE-2026-22869
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-22869
-
cpe:2.3:a:eigent:eigent:0.0.1
-
cpe:2.3:a:eigent:eigent:0.0.10
-
cpe:2.3:a:eigent:eigent:0.0.11
-
cpe:2.3:a:eigent:eigent:0.0.12
-
cpe:2.3:a:eigent:eigent:0.0.13
-
cpe:2.3:a:eigent:eigent:0.0.14
-
cpe:2.3:a:eigent:eigent:0.0.15
-
cpe:2.3:a:eigent:eigent:0.0.16
-
cpe:2.3:a:eigent:eigent:0.0.17
-
cpe:2.3:a:eigent:eigent:0.0.18
-
cpe:2.3:a:eigent:eigent:0.0.19
-
cpe:2.3:a:eigent:eigent:0.0.2
-
cpe:2.3:a:eigent:eigent:0.0.20
-
cpe:2.3:a:eigent:eigent:0.0.21
-
cpe:2.3:a:eigent:eigent:0.0.22
-
cpe:2.3:a:eigent:eigent:0.0.23
-
cpe:2.3:a:eigent:eigent:0.0.24
-
cpe:2.3:a:eigent:eigent:0.0.25
-
cpe:2.3:a:eigent:eigent:0.0.26
-
cpe:2.3:a:eigent:eigent:0.0.27
-
cpe:2.3:a:eigent:eigent:0.0.28
-
cpe:2.3:a:eigent:eigent:0.0.29
-
cpe:2.3:a:eigent:eigent:0.0.3
-
cpe:2.3:a:eigent:eigent:0.0.30
-
cpe:2.3:a:eigent:eigent:0.0.4
-
cpe:2.3:a:eigent:eigent:0.0.5
-
cpe:2.3:a:eigent:eigent:0.0.51
-
cpe:2.3:a:eigent:eigent:0.0.52
-
cpe:2.3:a:eigent:eigent:0.0.53
-
cpe:2.3:a:eigent:eigent:0.0.54
-
cpe:2.3:a:eigent:eigent:0.0.55
-
cpe:2.3:a:eigent:eigent:0.0.56
-
cpe:2.3:a:eigent:eigent:0.0.57
-
cpe:2.3:a:eigent:eigent:0.0.58
-
cpe:2.3:a:eigent:eigent:0.0.59
-
cpe:2.3:a:eigent:eigent:0.0.6
-
cpe:2.3:a:eigent:eigent:0.0.60
-
cpe:2.3:a:eigent:eigent:0.0.61
-
cpe:2.3:a:eigent:eigent:0.0.62
-
cpe:2.3:a:eigent:eigent:0.0.63
-
cpe:2.3:a:eigent:eigent:0.0.64
-
cpe:2.3:a:eigent:eigent:0.0.65
-
cpe:2.3:a:eigent:eigent:0.0.66
-
cpe:2.3:a:eigent:eigent:0.0.67
-
cpe:2.3:a:eigent:eigent:0.0.68
-
cpe:2.3:a:eigent:eigent:0.0.7
-
cpe:2.3:a:eigent:eigent:0.0.70
-
cpe:2.3:a:eigent:eigent:0.0.71
-
cpe:2.3:a:eigent:eigent:0.0.72
-
cpe:2.3:a:eigent:eigent:0.0.73
-
cpe:2.3:a:eigent:eigent:0.0.74
-
cpe:2.3:a:eigent:eigent:0.0.75
-
cpe:2.3:a:eigent:eigent:0.0.77
-
cpe:2.3:a:eigent:eigent:0.0.8
-
cpe:2.3:a:eigent:eigent:0.0.9