CVE-2026-55158: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in wktk conflibot
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automatically interprets those characters as commands without maintainer interaction. The commands execute on a runner with base-repository secrets and a write-scoped GITHUB_TOKEN, allowing arbitrary command execution, secret or token exfiltration, unauthorized pushes, and other token abuse. The fixed implementations in src/index.ts and src/conflibot.ts use execFile or spawn argument arrays, and the v2 line also uses numeric pull-request refs rather than branch names. This issue is fixed in versions 1.2.1 and 2.0.0.
AI Analysis
Technical Summary
Conflibot, a tool that warns about pull request merge conflicts, prior to version 1.2.1, constructs git commands by directly interpolating the pull request branch name (head.ref) into shell commands executed via exec. In the pull_request_target GitHub Actions configuration, an attacker can submit a pull request from a fork with a branch name containing shell metacharacters. These characters are interpreted as commands by the runner, leading to arbitrary command execution with access to repository secrets and a write-scoped GITHUB_TOKEN. This allows attackers to exfiltrate secrets, perform unauthorized pushes, and abuse tokens. The vulnerability is addressed in versions 1.2.1 and 2.0.0 by switching to execFile or spawn with argument arrays and using numeric pull-request references instead of branch names.
Potential Impact
An attacker can execute arbitrary commands on the GitHub Actions runner with access to sensitive repository secrets and a write-scoped GITHUB_TOKEN. This enables secret and token exfiltration, unauthorized code pushes, and other abuses of repository credentials. The vulnerability has a CVSS score of 9.1 (critical), indicating a high impact on confidentiality and integrity without requiring privileges or user interaction.
Mitigation Recommendations
A fix is available in Conflibot versions 1.2.1 and 2.0.0. Users should upgrade to one of these versions to remediate the vulnerability. No additional mitigation is required if these versions are in use.
CVE-2026-55158: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in wktk conflibot
Description
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automatically interprets those characters as commands without maintainer interaction. The commands execute on a runner with base-repository secrets and a write-scoped GITHUB_TOKEN, allowing arbitrary command execution, secret or token exfiltration, unauthorized pushes, and other token abuse. The fixed implementations in src/index.ts and src/conflibot.ts use execFile or spawn argument arrays, and the v2 line also uses numeric pull-request refs rather than branch names. This issue is fixed in versions 1.2.1 and 2.0.0.
CVSS v3.1
Score 9.1critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Conflibot, a tool that warns about pull request merge conflicts, prior to version 1.2.1, constructs git commands by directly interpolating the pull request branch name (head.ref) into shell commands executed via exec. In the pull_request_target GitHub Actions configuration, an attacker can submit a pull request from a fork with a branch name containing shell metacharacters. These characters are interpreted as commands by the runner, leading to arbitrary command execution with access to repository secrets and a write-scoped GITHUB_TOKEN. This allows attackers to exfiltrate secrets, perform unauthorized pushes, and abuse tokens. The vulnerability is addressed in versions 1.2.1 and 2.0.0 by switching to execFile or spawn with argument arrays and using numeric pull-request references instead of branch names.
Potential Impact
An attacker can execute arbitrary commands on the GitHub Actions runner with access to sensitive repository secrets and a write-scoped GITHUB_TOKEN. This enables secret and token exfiltration, unauthorized code pushes, and other abuses of repository credentials. The vulnerability has a CVSS score of 9.1 (critical), indicating a high impact on confidentiality and integrity without requiring privileges or user interaction.
Mitigation Recommendations
A fix is available in Conflibot versions 1.2.1 and 2.0.0. Users should upgrade to one of these versions to remediate the vulnerability. No additional mitigation is required if these versions are in use.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2qvg-qr73-mqxp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55158"]
- Ecosystems
- ["GitHub Actions"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a833354bf8831d5392a4df5
Added to database: 08/17/2026, 16:14:12 UTC
Last enriched: 09/23/2026, 02:03:23 UTC
Last updated: 10/02/2026, 02:46:05 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.