# CVE-2026-41414

> Vulnerability · severity: **HIGH** (CVSS 7.4).

## Description

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.

## Key facts

- **CVE ID:** CVE-2026-41414
- **Published:** 2026-04-24
- **CVSS severity:** HIGH
- **CVSS base score:** 7.4
- **CWE codes:** CWE-94

## Affected products

- `skim-rs:skim`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41414

## Citation

> AI Analytics. CVE-2026-41414. Retrieved 2026-07-25 from https://api.ai-analytics.org/cve/CVE-2026-41414. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*