Junglewise Threat Intelligence

CVE-2026-34243: njzjz wenxian command injection in GitHub Actions workflow

CVE-2026-34243 · Severity: critical · CVSS 9.8 · Published 2026-03-31

Executive brief

wenxian is a tool used to automatically generate bibliographic (BibTeX) entries for academic papers. A security flaw in its automated GitHub workflows allows any user to execute malicious commands by simply posting a specially crafted comment on a project issue. This could allow an attacker to steal sensitive repository data, access internal credentials, or compromise the software's build process.

Technical details

A command injection vulnerability exists in the GitHub Actions workflow of the wenxian repository due to the unsafe interpolation of untrusted user input. The workflow triggers on 'issue_comment' events and directly embeds the '${{ github.event.comment.body }}' context into a shell 'run' step without sanitization. An attacker can exploit this by crafting an issue comment containing shell metacharacters (e.g., backticks or semicolons) to break out of the intended command and execute arbitrary code on the GitHub runner. This provides access to the 'GITHUB_TOKEN' and the runner's environment. As of publication, no patch is available; users are advised to modify workflows to use environment variables for handling untrusted input.

Affected products

  • njzjz wenxian <= 0.3.1

Timeline

  • 2026-03-27: advisory: GitHub Security Advisory GHSA-r4fj-r33x-8v88 published
  • 2026-03-31: disclosed: CVE-2026-34243 published to NVD

References