#1136·uCrop

Security finding — possible pull_request_target pattern

Author: UserboyprocodeCreated May 28, 2026Updated May 28, 2026

Automated scan from flagged a pull_request_target workflow that checks out the PR head SHA/ref. That's the pattern of the classic GitHub Actions RCE — but exploitability depends on your guards. I verified the pattern, not exploitability.