CVE-2026-27701 is a JavaScript injection vulnerability in LiveCode’s i18n-update-pull GitHub Actions workflow prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11. The workflow interpolates the title of a pull request (associated with the triggering issue comment) directly into an actions/github-script JavaScript block via a GitHub Actions template expression, without proper escaping/quoting. An attacker can open a pull request with a crafted title such that attacker-controlled JavaScript is injected into the workflow’s script context and executed during CI, running with the privileges of the CI bot token derived from CI_APP_ID / CI_APP_PRIVATE_KEY.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
i18n-update-pull workflow or modify it to avoid interpolating untrusted PR metadata into executable JavaScript (e.g., pass data via environment variables/JSON and parse safely, ensure proper escaping/quoting, and avoid actions/github-script eval-like patterns). Additionally, restrict workflow triggers and reduce token permissions/secret exposure for workflows that can be influenced by untrusted PR content.Patch, then assume compromise.
e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, which fixes the vulnerable interpolation in the i18n-update-pull workflow.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.