Skip to content

CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration

High severity GitHub Reviewed Published May 13, 2026 in coreshop/CoreShop • Updated May 14, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts