PT-2026-21922 · Live Codes · Livecode

·

CVE-2026-27701

·

Published

2026-02-25

·

Updated

2026-02-28

CVSS v4.0

8.8

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions LiveCode versions prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11
Description LiveCode is an open-source, client-side code playground. The i18n-update-pull GitHub Actions workflow is susceptible to JavaScript injection prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11. The title of a Pull Request is directly interpolated into a JavaScript block within the actions/github-script action using a GitHub Actions template expression. An attacker can inject arbitrary JavaScript by creating a Pull Request with a specially crafted title. This injected JavaScript executes with the permissions of the CI bot token (CI APP ID / CI APP PRIVATE KEY), potentially allowing for the exfiltration of repository secrets and unauthorized operations via the GitHub API.
Recommendations Update LiveCode to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27701
GHSA-XH9W-5859-X97J

Affected Products

Livecode