


Perceptive Security
SOC/SIEM Consultancy

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vuln…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 21:06:41
Source:
nvd.nist.gov
Supply Chain & Dependencies, Security Tools
The Sherlock social media account hunting tool has a critical command injection vulnerability in its GitHub Actions workflow validate_modified_targets.yml prior to version 0.16.1. The vulnerability exists in the pull_request_target trigger and allows any GitHub user to execute arbitrary commands on the CI runner and exfiltrate the GITHUB_TOKEN by simply opening a pull request. No approval, review, or merge is required for exploitation. The issue has been fixed in version 0.16.1.
Technical details
Mitigation steps:
Affected products:
Sherlock
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44590
https://github.com/sherlock-project/sherlock/security/advisories/GHSA-v6wr-ccr4-x8g9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
