Impact
The vulnerability lies in the disc.yml GitHub Actions workflow, which triggers the createDiscussion mutation on any off‑topic issue created or edited without checking whether a discussion has already been spawned. A user who repeatedly edits an off‑topic issue can therefore create many duplicate discussions for the same issue, resulting in discussion spam and excess moderation effort. The weakness is classified as CWE‑799.
Affected Systems
OmniBlocks’ monorepo is affected. No specific version range is supplied, and the issue is mitigated by applying the commit that fixes the workflow. Users running the repository without this commit are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it with any account that can edit issues in the repository; the attack vector is inferred to be local to the repository and requires no external network interaction.
OpenCVE Enrichment