{"id":"CVE-2026-27701","summary":"LiveCodes vulnerable to JavaScript Injection via untrusted PR title in i18n-update-pull workflow","details":"LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitHub Actions workflow is vulnerable to JavaScript injection. The title of the Pull Request associated with the triggering issue comment is interpolated directly into a `actions/github-script` JavaScript block using a GitHub Actions template expression. An attacker who opens a PR with a crafted title can inject arbitrary JavaScript that executes with the privileges of the CI bot token (`CI_APP_ID` / `CI_APP_PRIVATE_KEY`), enabling exfiltration of repository secrets and unauthorized GitHub API operations. Commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11 fixes the issue.","aliases":["GHSA-xh9w-5859-x97j"],"modified":"2026-08-12T03:51:42.357006496Z","published":"2026-02-25T15:06:17.617Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27701.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"e151c64c2bd80d2d53ac1333f1df9429fe6a1a11"}]}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27701.json"},{"type":"ADVISORY","url":"https://github.com/live-codes/livecodes/security/advisories/GHSA-xh9w-5859-x97j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27701"},{"type":"FIX","url":"https://github.com/live-codes/livecodes/commit/e151c64c2bd80d2d53ac1333f1df9429fe6a1a11"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/live-codes/livecodes","events":[{"introduced":"0"},{"fixed":"e151c64c2bd80d2d53ac1333f1df9429fe6a1a11"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v48","sdk-v0.13.0","v47","sdk-v0.12.0","sdk-v0.11.1","v46","sdk-v0.11.0","v45","sdk-v0.10.0","v44","sdk-v0.9.1","v43","sdk-v0.9.0","v42","sdk-v0.8.0","v39","v38","sdk-v0.7.2","v37","sdk-v0.7.1","v36","sdk-v0.7.0","v35","v34","sdk-v0.6.0","v33","v32","v31","v3","v4","v5","v6","v7","v8","v9","v10","v11","v12","v13","v14","v15","v16","v17","v19","v20","v21","v22","v23","v24","v18","v30","v29","v28","v27","sdk-v0.5.0","v26","v25","sdk-v0.4.0","sdk-v0.3.0","sdk-v0.2.1","sdk-v0.2.0","sdk-v0.1.2","sdk-v0.1.1","sdk-v0.1.0","sdk-v0.0.3","v0.4.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27701.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}]}