Executive brief
act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act
Affected products
- Go github.com/nektos/act
Junglewise Threat Intelligence
CVE-2026-34041 · Severity: medium · CVSS 4 · Published 2026-04-02
Technologies: github.com/nektos/act (Go). Vendors: Go.
act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act