OVERVIEW CVE-2026-40316 is a critical remote code execution vulnerability affecting OWASP BLT versions prior to 2.1.1. The flaw exists in the GitHub Actions workflow file .github/workflows/regenerate-migrations.yml, which improperly handles untrusted pull request content. By exploiting insecure workflow design, an attacker can execute arbitrary Python code in the privileged CI environment where the build process has full access to the GITHUB_TOKEN and repository secrets. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH) with a network attack vector requiring no special privileges or authentication, though maintainer action (applying a label) is required as a trigger. The attack complexity is low, and successful exploitation results in complete confidentiality, integrity, and availability compromise. The threat is particularly acute because it enables access to sensitive credentials and repository control, creating significant supply chain attack potential. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild, as indicated by the vulnerability's absence from CISA's Known Exploited Vulnerabilities catalog and its inactive status on threat tracking lists. The EPSS score of 0.00065 suggests minimal likelihood of exploitation attempts compared to other vulnerabilities. A patch is expected in version 2.1.1, and users should immediately upgrade to this version or implement workflow restrictions to require explicit code review approval before the regenerate-migrations label can trigger the vulnerable workflow.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1CPE matchmatch criteria | cpe:2.3:a:owasp:owasp_blt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.