PT-2026-30892 · Emissary · Emissary

Brennantm

·

Published

2026-04-06

·

Updated

2026-04-14

·

CVE-2026-35580

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emissary versions prior to 8.39.0
Description Emissary is a P2P based data-driven workflow engine. Prior to version 8.39.0, GitHub Actions workflow files contained shell injection points. User-controlled workflow dispatch inputs were interpolated directly into shell commands via the ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, potentially leading to repository poisoning and supply chain compromise affecting downstream users.
Recommendations Update to version 8.39.0 or higher.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35580
GHSA-3G6G-GQ4R-XJM9
OPENSUSE-SU-2026:10540-1

Affected Products

Emissary