Description
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automatically interprets those characters as commands without maintainer interaction. The commands execute on a runner with base-repository secrets and a write-scoped GITHUB_TOKEN, allowing arbitrary command execution, secret or token exfiltration, unauthorized pushes, and other token abuse. The fixed implementations in src/index.ts and src/conflibot.ts use execFile or spawn argument arrays, and the v2 line also uses numeric pull-request refs rather than branch names. This issue is fixed in versions 1.2.1 and 2.0.0.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via command injection in GitHub Actions
Action: Immediate Patch
AI Analysis

Impact

Conflibot warns of merge conflicts between open pull requests, but before version 1.2.1 its source builds git checkout, git merge, and git format‑patch commands by inserting the pull request’s head.ref value directly into the shell command string. In the documented pull_request_target configuration, an attacker can open a pull request—also from a fork—whose branch name contains shell metacharacters; the workflow then interprets these characters as additional shell commands. When these commands run on the GitHub Actions runner, they execute with the repository’s base‑repository secrets and a write‑scoped GITHUB_TOKEN, allowing arbitrary command execution, secret theft, unauthorized pushes, and other token abuse. The flaw is a classic command injection (CWE‑78), and it can be triggered with no interaction from the repository maintainers. The fix in v1.2.1 and v2.0.0 replaces string interpolation with execFile or spawn argument arrays, and the v2 line also switches to numeric pull‑request references rather than branch names.

Affected Systems

The vulnerability affects Conflibot deployments provided by wktk. Versions prior to v1.2.1 and v2.0.0 are affected; upgrading to v1.2.1 or any later release eliminates the trait of interpolating branch names into shell commands.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, and the EPSS score of < 1% suggests a low probability of exploitation, though the zero‑effort and high‑value target of this vulnerability make it a meaningful risk. The flaw is exploitable in public pull_request_target workflows, a common GitHub Actions pattern. The attacker only needs to create a pull request from a fork with a specially crafted branch name. Once the workflow runs, the injected commands execute with the runner’s base‑repository secrets and a write‑scoped GITHUB_TOKEN, providing a foothold for full compromise. The flaw is not listed in the CISA KEV catalog but the potential impact is high enough that rapid remediation is warranted.

Generated by OpenCVE AI on September 20, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Conflibot to version 1.2.1 or later, or to the latest 2.0.0 release, to remove the shell interpolation code.
  • In environments where a patch cannot be applied immediately, remove or temporarily disable the pull_request_target workflow that uses Conflibot until the update is applied.
  • Restrict pull_request_target workflows to accept only pull requests from trusted collaborators and enforce branch‑name whitelisting so that any branch names containing shell metacharacters cannot be processed.

Generated by OpenCVE AI on September 20, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2qvg-qr73-mqxp conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wktk
Wktk conflibot
Vendors & Products Wktk
Wktk conflibot

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automatically interprets those characters as commands without maintainer interaction. The commands execute on a runner with base-repository secrets and a write-scoped GITHUB_TOKEN, allowing arbitrary command execution, secret or token exfiltration, unauthorized pushes, and other token abuse. The fixed implementations in src/index.ts and src/conflibot.ts use execFile or spawn argument arrays, and the v2 line also uses numeric pull-request refs rather than branch names. This issue is fixed in versions 1.2.1 and 2.0.0.
Title Conflibot: Command injection via crafted pull request branch names under pull_request_target
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:42:35.993Z

Reserved: 2026-06-16T15:13:28.165Z

Link: CVE-2026-55158

cve-icon Vulnrichment

Updated: 2026-09-17T14:42:23.484Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:18.593

Modified: 2026-09-29T19:07:47.037

Link: CVE-2026-55158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')