
Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml, snapshot of coreshop/CoreShop@cc1e3f54
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
coreshop/CoreShopat commitcc1e3f547228ec5ebfc1dc0472f9a3cc5f4137a4(2026-04-16), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-16; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
CoreShop - Pimcore enhanced eCommerce
CoreShop harnesses Pimcore's advanced features for unmatched efficiency and customization in your online store. Dive into a seamless blend of cutting-edge technology and user-friendly interfaces, crafting an eCommerce experience that transcends ordinary transactions.
^12.3Read our Documentation for the Installation Guide here
Discover the full potential of CoreShop through our interactive demos. Read more about this here
Copyright: CoreShop GmbH For licensing details please visit LICENSE.md