Improper access control in Sakura Editor - #VU145348
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute attacker-controlled code with repository write privileges and access repository secrets.
The vulnerability exists due to improper access control in the GitHub Actions pull_request_target workflow when processing a fork-based pull request on the opened event. A remote attacker can open a crafted pull request containing modified build scripts to execute attacker-controlled code with repository write privileges and access repository secrets.
No maintainer approval is required, and the workflow can run for a first-time contributor immediately upon pull request creation.