CVE-2026-34243
CRITICALwenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Title source: cnaDescription
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.
Scores
CVSS v3
9.8
EPSS
0.0007
EPSS Percentile
21.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
CWE-78
Status
published
Products (3)
GitHub Actions/njzjz/wenxian
0GitHub Actions
njzjz/wenxian
< 0.3.1
njzjz/wenxian
<= 0.3.1
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026