CVE-2026-44590 affects Sherlock versions prior to 0.16.1. The vulnerability is in the project's GitHub Actions workflow file validate_modified_targets.yml, which is exposed through the pull_request_target trigger. Because the workflow processes attacker-controlled pull request context in an unsafe way, any GitHub user can open a pull request and trigger command injection on the CI runner. The issue allows arbitrary command execution in the GitHub Actions environment without requiring pull request approval, review, or merge. The advisory states that the flaw can also be used to exfiltrate the repository's GITHUB_TOKEN. The issue is fixed in Sherlock 0.16.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact exploit PoC consisting of a single Python script (`poc.py`), a README, and a license file. The script is a self-contained stdlib-only automation tool targeting CVE-2026-44590 in `sherlock-project/sherlock`, specifically a command injection flaw in the `validate_modified_targets.yml` GitHub Actions workflow triggered via `pull_request_target`. Core capability: the exploit automates the full attack chain against a vulnerable fork of the Sherlock repository. It can create or reuse a fork, optionally reset the fork to the vulnerable pre-fix commit `271608fb22209ef15a775cce88dd07fd4fa76483`, create and push a malicious branch, open a PR, trigger the workflow, and verify command execution through an OAST callback. In `--mode exfil`, it escalates from simple command execution to credential theft by extracting the workflow `GITHUB_TOKEN` from `git config --list` output captured via OAST, decoding the Basic auth blob into `x-access-token:ghs_...`, and then using the stolen token to approve the same PR through the GitHub API. The exploit is not merely a detector: it performs active exploitation and post-exploitation action. The README explicitly describes the impact as arbitrary command execution in privileged CI, token exfiltration, and PR auto-approval without human interaction. The script also handles operational details such as locating or spawning `interactsh-client`, polling OAST logs for markers or tokens, invoking `gh api`, and cleaning up the remote PoC branch and temporary files. Repository structure is minimal: - `poc.py`: main exploit entry point and all automation logic. - `README.md`: detailed usage, modes, requirements, and sample output. - `LICENSE`: MIT license. Notable observables include the upstream repository slug `sherlock-project/sherlock`, the targeted workflow file `validate_modified_targets.yml`, the repository data path `sherlock_project/resources/data.json`, GitHub-related authorization material matching `http.https://github.com/.extraheader=AUTHORIZATION: basic ...`, and dynamically generated interactsh OAST domains. Overall, this is an operational PoC for CI/CD supply-chain exploitation against a specific GitHub Actions workflow vulnerability, with both verification and token-exfiltration/PR-approval modes.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.