PT-2026-30892 · U.S. National Security Agency · Emissary

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35580

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35580

Affected Products

Emissary