Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target (CVE-2026-55158)

0
Critical
Published: 08/17/2026 (08/17/2026, 13:35:07 UTC)
Source: GCVE Database
Product: wktk/conflibot

Description

Versions of wktk/conflibot prior to 1.2.1 are vulnerable to command injection via crafted pull request branch names when used in workflows triggered by the pull_request_target event. The vulnerability arises because git commands are constructed using string interpolation and executed through a shell, allowing attacker-controlled branch names containing shell metacharacters to execute arbitrary commands. This can lead to unauthorized access to repository secrets and tokens, enabling secret exfiltration and repository write access without maintainer interaction. The issue is fixed in versions 1.2.1 and 2.0.0 by avoiding shell command execution and referencing pull requests by number instead of branch name.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

GitHub Actionsghsa
wktk/conflibot
Affected versions
<1.2.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 16:27:51 UTC

Technical Analysis

wktk/conflibot versions before 1.2.1 build git commands via string interpolation and execute them through a shell, interpolating attacker-controlled pull request branch names. When run on the pull_request_target event, the workflow has access to repository secrets and a write-scoped GITHUB_TOKEN. An attacker can craft a pull request with a branch name containing shell metacharacters to execute arbitrary commands on the runner with these elevated privileges. This allows exfiltration of secrets and token abuse without any special privileges or maintainer interaction. The vulnerability is fixed in versions 1.2.1 and 2.0.0 by switching to argument arrays for git commands and referencing pull requests by number, preventing shell interpretation of branch names.

Potential Impact

An attacker can achieve arbitrary command execution on the GitHub Actions runner with access to repository secrets and a write-scoped GITHUB_TOKEN. This enables exfiltration of sensitive information and unauthorized repository modifications. The vulnerability requires no special privileges or maintainer interaction and is exploitable by simply opening a crafted pull request. The CVSS score is 9.1 (critical), reflecting the high impact on confidentiality and integrity.

Mitigation Recommendations

Upgrade wktk/conflibot to version 1.2.1 or later (including 2.0.0). These versions fix the vulnerability by avoiding shell command execution and referencing pull requests by number rather than branch name. There is no configuration-only workaround for affected versions. On GitHub-hosted runners, upgrading to wktk/conflibot@v2 is a drop-in replacement. Self-hosted runners require Node.js 24 support and git 2.38 or later to upgrade safely.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-2qvg-qr73-mqxp
Osv Schema Version
1.4.0
Aliases
["CVE-2026-55158"]
Ecosystems
["GitHub Actions"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6a833354bf8831d5392a4df5

Added to database: 08/17/2026, 16:14:12 UTC

Last enriched: 08/17/2026, 16:27:51 UTC

Last updated: 08/18/2026, 01:04:53 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses