Impact
An issue title submitted to the githubtoplanguages repository is interpolated directly into a Bash variable assignment within the discord‑issue.yml workflow. The title is not sanitized before shell parsing, allowing the use of shell command-substitution syntax. When an issue is opened or closed, the malformed title triggers arbitrary command execution on the GitHub Actions runner, which can then manipulate the Discord webhook or expose the webhook secret, reflecting a classic command‑injection vulnerability.
Affected Systems
The danger exists wherever the githubtoplanguages workflow is present, primarily the official gouef/githubtoplanguages repository and any forks that deploy the discord‑issue.yml file unchanged. No explicit version range is listed, so any instance of the workflow prior to the corrective commit is susceptible.
Risk and Exploitability
The CVSS score of 7.1 represents a moderate‑to‑high severity, and EPSS score is <1%, the vulnerability is not currently catalogued in CISA KEV. Exploitation requires the attacker to create or edit an issue title in a repository that runs the workflow, which is typically possible with any repository contributor or in public projects. If the attacker succeeds, they can execute code on the runner and tamper with or impersonate trusted Discord bot notifications, potentially leaking secrets.
OpenCVE Enrichment