CVEs
·Shriyans Sudhi

CVE-2026-55378: Command injection in JS Recon's PR Branch Checker workflow

The story

I wrote this bug.

In August 2025 I added a small GitHub Actions workflow to JS Recon that checks whether a pull request targets the right branch and leaves a comment if it doesn't. It worked, so I never looked at it again.

About ten months later I came back to it and realised the comment was built by dropping the PR's branch name and fork name straight into a shell command. Anyone on GitHub could have opened a PR with a crafted branch name and run commands on the runner. For a security tool that people install and run against real targets, that is a supply-chain problem, not just a CI problem.

So I patched it and published an advisory against my own project, which was assigned CVE-2026-55378. Lesson learned: every ${{ github.* }} value that a stranger can influence is attacker input.

Official

Description

The PR Branch Checker workflow (.github/workflows/pr_checker.yml) interpolated two untrusted values, github.head_ref (the source branch name) and github.event.pull_request.head.repo.full_name (the fork's full name), directly into a shell gh pr comment command via unquoted environment variables:

env:
  BRANCH_NAME: ${{ github.head_ref }}
  SOURCE_REPO: ${{ github.event.pull_request.head.repo.full_name }}
run: |
  gh pr comment $PR_NUMBER --body "... (source: `$SOURCE_REPO:$BRANCH_NAME`)."

Any GitHub user who can open a pull request targeting main could craft a branch name or fork name containing shell metacharacters (backticks, $(...), &&, ;, newlines) to execute arbitrary commands in the Actions runner. The runner had pull-requests: write permission and access to GITHUB_TOKEN, which could have been used to tamper with the repository or stage a malicious release of the scanner.

Remediation

Fixed in commit 447876c (2026-06-12). The fix removes BRANCH_NAME and SOURCE_REPO from the workflow entirely and replaces the dynamic comment body with static text. No user action is required: the vulnerability was in CI infrastructure, not in the published package.

See also: GitHub Actions: understanding the risk of script injections

Timeline

Date format: YYYY-MM-DD

  • Introduced: 2025-08-07
  • Fixed: 2026-06-12
  • Published: 2026-06-22