CVE-2026-34243 affects wenxian, a tool for generating BibTeX files from identifiers such as DOI, PMID, arXiv ID, or paper title. In versions 0.3.1 and earlier, a GitHub Actions workflow incorporates untrusted user-controlled input from issue_comment.body directly into a shell run: command. Because the workflow fails to safely isolate or sanitize this input before passing it to the shell, an attacker can inject additional shell metacharacters or commands. Successful exploitation results in arbitrary command execution within the context of the GitHub Actions runner. The vulnerable condition is in the repository’s CI/CD workflow logic rather than the core application runtime itself.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
GITHUB_TOKEN, exfiltration of repository contents or workflow secrets available to the job, tampering with build or automation outputs, and broader CI/CD pipeline compromise. Impact may extend to unauthorized repository actions performed with the runner’s effective privileges.If you can’t patch tonight, do this now.
github.event.comment.body, into any run: shell command. Treat all issue and comment content as hostile input. Use environment variables or structured inputs and quote or otherwise safely process them before use. Restrict workflow permissions to the minimum necessary, limit exposure of secrets and write-capable tokens to comment-triggered workflows, and disable or gate the vulnerable workflow until it is corrected.Patch, then assume compromise.
${{ github.event.comment.body }} is not embedded directly in shell commands. Refactor the workflow to pass comment content through an environment variable, such as COMMENT_BODY, and then handle it safely within the script without shell interpolation of untrusted data. Upgrade to a fixed workflow revision once available, or manually replace the vulnerable workflow content in deployments based on wenxian 0.3.1 or earlier.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 44-file Python project is primarily the `wenxian` citation generator: its CLI (`wenxian/__main__.py`) accepts DOI, PMID, arXiv, or title inputs; feeder modules query Crossref, arXiv, ChemRxiv, PubMed/NCBI, and Semantic Scholar; and `reference.py` renders BibTeX, text, or Markdown citations. It also provides a composite GitHub Action, a deprecated Pyodide browser interface, an agent skill, and pytest coverage. The security-relevant proof of concept is `.github/workflows/comment.yaml`. Its `issue_comment` job is activated when a comment contains `@njzjz-bot`, but constructs a shell command by directly substituting `${{ github.event.comment.body }}` inside double quotes. GitHub expression substitution occurs before Bash executes, so quote-breaking input can inject commands. The job subsequently runs the local composite action and posts results through `gh issue comment` with `issues: write` permission. The repository contains no ready-made exploit string or malicious post-exploitation payload, but it is a credible lab reproduction of a GitHub Actions command-injection condition rather than a detection-only script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.