CVE-2026-55378: Command injection in JS Recon's PR Branch Checker workflow
- CVE-2026-55378 / GHSA-w9cj-mg3x-qjm4
- CVSS 4.0 Score: 9.3 (Critical)
- CVSS 4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- CWE(s): CWE-78 OS Command Injection
The story
I wrote this bug.
In August 2025 I added a small GitHub Actions workflow to JS Recon that checks whether a pull request targets the right branch and leaves a comment if it doesn't. It worked, so I never looked at it again.
About ten months later I came back to it and realised the comment was built by dropping the PR's branch name and fork name straight into a shell command. Anyone on GitHub could have opened a PR with a crafted branch name and run commands on the runner. For a security tool that people install and run against real targets, that is a supply-chain problem, not just a CI problem.
So I patched it and published an advisory against my own project, which was assigned CVE-2026-55378. Lesson learned: every ${{ github.* }} value that a stranger can influence is attacker input.
Official
Description
The PR Branch Checker workflow (.github/workflows/pr_checker.yml) interpolated two untrusted values, github.head_ref (the source branch name) and github.event.pull_request.head.repo.full_name (the fork's full name), directly into a shell gh pr comment command via unquoted environment variables:
env:
BRANCH_NAME: ${{ github.head_ref }}
SOURCE_REPO: ${{ github.event.pull_request.head.repo.full_name }}
run: |
gh pr comment $PR_NUMBER --body "... (source: `$SOURCE_REPO:$BRANCH_NAME`)."Any GitHub user who can open a pull request targeting main could craft a branch name or fork name containing shell metacharacters (backticks, $(...), &&, ;, newlines) to execute arbitrary commands in the Actions runner. The runner had pull-requests: write permission and access to GITHUB_TOKEN, which could have been used to tamper with the repository or stage a malicious release of the scanner.
Remediation
Fixed in commit 447876c (2026-06-12). The fix removes BRANCH_NAME and SOURCE_REPO from the workflow entirely and replaces the dynamic comment body with static text. No user action is required: the vulnerability was in CI infrastructure, not in the published package.
See also: GitHub Actions: understanding the risk of script injections
Timeline
Date format: YYYY-MM-DD
- Introduced: 2025-08-07
- Fixed: 2026-06-12
- Published: 2026-06-22