PT-2026-21922 · Live Codes · Livecode

Nekros1Xx

·

Published

2026-02-25

·

Updated

2026-02-28

·

CVE-2026-27701

CVSS v4.0

8.8

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions LiveCode versions prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11
Description LiveCode is an open-source, client-side code playground. The i18n-update-pull GitHub Actions workflow is susceptible to JavaScript injection prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11. The title of a Pull Request is directly interpolated into a JavaScript block within the actions/github-script action using a GitHub Actions template expression. An attacker can inject arbitrary JavaScript by creating a Pull Request with a specially crafted title. This injected JavaScript executes with the permissions of the CI bot token (CI APP ID / CI APP PRIVATE KEY), potentially allowing for the exfiltration of repository secrets and unauthorized operations via the GitHub API.
Recommendations Update LiveCode to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-27701
GHSA-XH9W-5859-X97J

Affected Products

Livecode