Junglewise Threat Intelligence

CVE-2026-34041: GO-2026-4891 - act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act

CVE-2026-34041 · Severity: medium · CVSS 4 · Published 2026-04-02

Technologies: github.com/nektos/act (Go). Vendors: Go.

Executive brief

act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act

Affected products

  • Go github.com/nektos/act

Related threats