Junglewise Threat Intelligence

CVE-2026-54344: ToolJet OS command injection in GitHub Actions deployment workflow

CVE-2026-54344 · Severity: medium · CVSS 4.7 · Published 2026-07-08

Technologies: ToolJet. Vendors: ToolJet.

Executive brief

ToolJet is an open-source platform used by businesses to build internal software tools. A security flaw in its automated testing and deployment system allowed any GitHub user to execute malicious commands by simply commenting on a public pull request. This could lead to the theft of sensitive credentials, including API keys for cloud infrastructure and email services, potentially compromising the company's entire deployment environment.

Technical details

A command injection vulnerability exists in ToolJet's 'render-preview-deploy.yml' GitHub Actions workflow. The workflow directly interpolates the 'github.event.comment.body' context into a bash script within a 'run' step without sanitization or using environment variables. Because the workflow triggers on any comment containing '/deploy-ee' without verifying the author's permissions, an unauthenticated attacker can craft a comment that breaks out of the bash conditional to execute arbitrary code on the CI runner. This allows for the exfiltration of sensitive secrets, including RENDER_API_KEY, CUSTOM_GITHUB_TOKEN, and SMTP credentials. The issue is fixed in version 3.20.180 by using environment variables for shell expansion and adding author association checks.

Affected products

  • ToolJet ToolJet < 3.20.180

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory GHSA-4pm2-w6g5-28mm published
  • 2026-07-08: disclosed: CVE-2026-54344 published to NVD
  • 2026-07-08: patched: Fixed in version 3.20.180

References

Related threats