CVE-2026-31900 affects the GitHub Action provided by Black, the Python code formatter. When the action is configured with use_pyproject: true, it reads the Black version from the repository's pyproject.toml. A malicious pull request can modify pyproject.toml to specify a direct URL reference to an attacker-controlled repository instead of a trusted package source. If the workflow processes that pull request and installs or resolves the referenced package, attacker-controlled code can execute in the context of the GitHub Actions runner. This is an input validation failure in how the action accepts and uses version information sourced from repository-controlled configuration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small proof-of-concept lab demonstrating CVE-2026-31900, described as remote code execution in the psf/black GitHub Action when use_pyproject: true is enabled. The repo is not a full exploit framework; it is a minimal vulnerable lab composed of a GitHub Actions workflow, a benign Python sample file, a pyproject.toml, and documentation. The core issue is in .github/workflows/black.yml, which runs psf/black@26.1.0 with use_pyproject: true on both push and pull_request. According to the README, affected versions validate the Black dependency string with an overly permissive regex, allowing a PEP 508 direct URL requirement instead of a pinned package version. An attacker who can modify pyproject.toml in a forked pull request can replace the dependency black==26.1.0 with an attacker-hosted package URL. When the workflow runs, pip installs that package and executes its setup.py, yielding arbitrary code execution on the CI runner. The README includes an example payload that uses curl to exfiltrate $GITHUB_TOKEN to an attacker-controlled HTTPS endpoint. The workflow also contains a diagnostic step that prints /tmp/exfil.txt if present, suggesting the lab may be used to observe exfiltration artifacts. app.py is incidental sample content for formatting and does not participate in exploitation. Overall, the repository’s purpose is to reproduce and explain a supply-chain style CI/CD exploit path against GitHub Actions rather than to deliver a standalone offensive tool.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.