CyberRota Analysis
AI-GeneratedA vulnerability exists in the Fork-PR Actions task that allows unauthorized access to a third private repository through the collaborative-owner branch due to a missing fork-PR guard. This could lead to exposure of sensitive data within private repositories. Organizations using Fork-PR Actions for repository management should prioritize addressing this issue to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)