Description
githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell command-substitution syntax can therefore execute commands on the GitHub Actions runner before the title is included in the Discord notification sent through DISCORD_WEBHOOK. Successful exploitation can manipulate or spoof trusted bot notifications and may expose the Discord webhook secret or other workflow environment data, depending on repository permissions. This issue is fixed by commit 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution
Action: Apply Patch
AI Analysis

Impact

An issue title submitted to the githubtoplanguages repository is interpolated directly into a Bash variable assignment within the discord‑issue.yml workflow. The title is not sanitized before shell parsing, allowing the use of shell command-substitution syntax. When an issue is opened or closed, the malformed title triggers arbitrary command execution on the GitHub Actions runner, which can then manipulate the Discord webhook or expose the webhook secret, reflecting a classic command‑injection vulnerability.

Affected Systems

The danger exists wherever the githubtoplanguages workflow is present, primarily the official gouef/githubtoplanguages repository and any forks that deploy the discord‑issue.yml file unchanged. No explicit version range is listed, so any instance of the workflow prior to the corrective commit is susceptible.

Risk and Exploitability

The CVSS score of 7.1 represents a moderate‑to‑high severity, and EPSS score is <1%, the vulnerability is not currently catalogued in CISA KEV. Exploitation requires the attacker to create or edit an issue title in a repository that runs the workflow, which is typically possible with any repository contributor or in public projects. If the attacker succeeds, they can execute code on the runner and tamper with or impersonate trusted Discord bot notifications, potentially leaking secrets.

Generated by OpenCVE AI on September 20, 2026 at 14:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the workflow file to the fixed commit 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027 so that ISSUE_TITLE is securely set or escaped before shell parsing.
  • Restrict the DISCORD_WEBHOOK secret by monitoring its use; consider rotating it if a compromise is suspected.
  • Limit who can push to or modify .github/workflows files by enabling branch protection rules and code review requirements to the workflow.

Generated by OpenCVE AI on September 20, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gouef
Gouef githubtoplanguages
Vendors & Products Gouef
Gouef githubtoplanguages

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell command-substitution syntax can therefore execute commands on the GitHub Actions runner before the title is included in the Discord notification sent through DISCORD_WEBHOOK. Successful exploitation can manipulate or spoof trusted bot notifications and may expose the Discord webhook secret or other workflow environment data, depending on repository permissions. This issue is fixed by commit 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027.
Title githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Gouef Githubtoplanguages
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:37:42.953Z

Reserved: 2026-06-30T20:21:25.813Z

Link: CVE-2026-58502

cve-icon Vulnrichment

Updated: 2026-09-17T16:37:35.180Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:26.193

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-58502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')