Junglewise Threat Intelligence

CVE-2026-54594: OmniBlocks monorepo discussion spam via GitHub Actions

CVE-2026-54594 · Severity: info · Published 2026-09-17

Executive brief

OmniBlocks is an open-source monorepo that uses a GitHub Actions workflow to automatically convert off-topic issues into discussions. A flaw in the workflow logic fails to prevent duplicate processing, allowing a user to repeatedly edit an off-topic issue and trigger multiple discussion creations for the same issue. This creates spam, wastes moderator time, and clutters the project's discussion forum.

Technical details

The vulnerability is a logic flaw in the GitHub Actions workflow .github/workflows/disc.yml. The workflow monitors issue creation and issue edit events and invokes the createDiscussion GraphQL mutation when an issue is classified as off-topic. However, the workflow does not check whether a discussion has already been created for a given issue, nor does it suppress duplicate runs. An attacker can repeatedly edit an off-topic issue's description before initial conversion completes, causing the workflow to execute multiple times and create multiple discussions from a single issue. No authentication bypass or code execution is involved; the attack surface is limited to users with issue creation rights. The vulnerability was fixed by commit 627e0f0a16a7d74b09128106b57dd7e85d2545df, which deletes the vulnerable workflow entirely.

Affected products

  • OmniBlocks OmniBlocks

Timeline

  • 2026-09-17: disclosed
  • 2026-06-06: patched: Workflow remediation committed on or after June 6, 2026

References