Description
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was already converted or otherwise suppressing duplicate runs. A user who creates one off-topic issue and repeatedly edits its description before conversion completes can therefore cause multiple discussions to be created for the same issue, producing discussion spam and additional moderation work. This issue is fixed with commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Moderation Disruption / Spam
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the disc.yml GitHub Actions workflow, which triggers the createDiscussion mutation on any off‑topic issue created or edited without checking whether a discussion has already been spawned. A user who repeatedly edits an off‑topic issue can therefore create many duplicate discussions for the same issue, resulting in discussion spam and excess moderation effort. The weakness is classified as CWE‑799.

Affected Systems

OmniBlocks’ monorepo is affected. No specific version range is supplied, and the issue is mitigated by applying the commit that fixes the workflow. Users running the repository without this commit are susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it with any account that can edit issues in the repository; the attack vector is inferred to be local to the repository and requires no external network interaction.

Generated by OpenCVE AI on September 19, 2026 at 01:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the repository to commit 627e0f0a16a7d74b09128106b57dd7e85d2545df, which contains the workflow remediation.
  • Temporarily disable or restrict the disc.yml workflow that runs on issue edits until the patch is applied.
  • Monitor the discussions tab for unexpected spikes and review issue handling policies to prevent further abuse.

Generated by OpenCVE AI on September 19, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Omniblocks
Omniblocks monorepo
Vendors & Products Omniblocks
Omniblocks monorepo
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was already converted or otherwise suppressing duplicate runs. A user who creates one off-topic issue and repeatedly edits its description before conversion completes can therefore cause multiple discussions to be created for the same issue, producing discussion spam and additional moderation work. This issue is fixed with commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.
Title OmniBlocks: Spamming in Discussions tab possible via disc.yml
Weaknesses CWE-799
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Omniblocks Monorepo
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:09:27.955Z

Reserved: 2026-06-15T19:45:23.539Z

Link: CVE-2026-54594

cve-icon Vulnrichment

Updated: 2026-09-18T20:09:24.148Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T20:16:51.670

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:45:16Z

Weaknesses
  • CWE-799

    Improper Control of Interaction Frequency