<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T00:22:09.262504+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278784</id>
    <title>EUVD-2026-278784</title>
    <updated>2026-10-09T00:22:09.319615+00:00</updated>
    <content>EUVD-2026-278784</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34243</id>
    <title>fkie_cve-2026-34243</title>
    <updated>2026-10-09T00:22:09.319654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r4fj-r33x-8v88</id>
    <title>GHSA-r4fj-r33x-8v88 — wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`</title>
    <updated>2026-10-09T00:22:09.319688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> GitHub Actions: njzjz/wenxian</p>
<p>#### Summary</p>
<p>A GitHub Actions workflow uses untrusted user input from `issue_comment.body` directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner.</p>
<p>#### Details</p>
<p>The workflow is triggered by `issue_comment`, which can be controlled by external users.
In the following step:</p>
<p>```bash
echo identifiers=$(echo "${{ github.event.comment.body }}" | grep -oE '@njzjz-bot .*' | head -n1 | cut -c12- | xargs) &gt;&gt; $GITHUB_OUTPUT
```</p>
<p>the value of `github.event.comment.body` is directly interpolated into a shell command inside `run:`.</p>
<p>Since GitHub Actions evaluates `${{ }}` before execution, attacker-controlled input is injected into the shell context without sanitization. This creates a command injection risk.</p>
<p>Additionally, the extracted value is later reused in another step that constructs output using backticks:</p>
<p>```bash
echo '@${{ github.event.comment.user.login }} Here is the BibTeX entry for `${{ steps.extract-identifiers.outputs.identifiers }}`:'
```</p>
<p>which may further propagate unsafe content.</p>
<p>#### PoC</p>
<p>1. Go to an issue in the repository
2. Post a comment such as:</p>
<p>`@njzjz-bot paper123" ) ; whoami ; #
`</p>
<p>3. Observe whether the command is executed or reflected in logs/output
&lt;img width="658" height="203" alt="poc" src="https://github.com/user-attachments/assets/084ac264-8cb9-4721-8279-26a1da9b891f" /&gt;</p>
<p>The injected payload successfully breaks out of the quoted context and executes arbitrary shell commands.</p>
<p>As shown in t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r4fj-r33x-8v88"/>
  </entry>
</feed>
