Back to CVE List

CVE-2026-34243

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-77
Source
GitHub
Vendor
actions
Product
njzjz/wenxian

External References

Discussion (0)

Add Comment

No comments yet. Be the first!