{"id":"CVE-2026-55576","summary":"MaaAssistantArknights: PR-title expression injection in release-preparation.yml","details":"MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork PR whose title starts with Release v could execute shell commands on the ubuntu-latest runner during the generate-changelog job. This vulnerability is fixed by commit cafc3946059e6337d2089d4fec8b6885ba17c332.","aliases":["GHSA-pqx2-5g66-f5w8"],"modified":"2026-07-19T03:31:09.657363192Z","published":"2026-07-15T21:02:14.524Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-78","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55576.json","unresolved_ranges":[{"extracted_events":[{"fixed":"cafc3946059e6337d2089d4fec8b6885ba17c332"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55576.json"},{"type":"ADVISORY","url":"https://github.com/MaaAssistantArknights/MaaAssistantArknights/security/advisories/GHSA-pqx2-5g66-f5w8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55576"},{"type":"FIX","url":"https://github.com/MaaAssistantArknights/MaaAssistantArknights/commit/cafc3946059e6337d2089d4fec8b6885ba17c332"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maaassistantarknights/maaassistantarknights","events":[{"introduced":"0"},{"fixed":"cafc3946059e6337d2089d4fec8b6885ba17c332"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v6.12.1","alpha/v6.12.2-alpha.1.d010.g0d2e18a476","alpha/v6.12.2-alpha.1.d008.gf7262208f0","alpha/v6.12.2-alpha.1.d002.ga73ce8efeb","v6.12.0","v6.12.0-beta.2","v6.12.0-beta.1","v6.11.1","v6.11.0","v6.11.0-beta.2","v6.11.0-beta.1","v6.10.7","v6.10.6","v6.10.5","v6.10.4","v6.10.3","v6.10.2","v6.10.1","v6.10.0","v6.10.0-beta.4","v6.10.0-beta.3","v6.10.0-beta.2","v6.10.0-beta.1","v6.9.5","v.6.9.4","v6.9.3","v6.9.2","v6.9.1","v6.9.0","v6.9.0-beta.3","v6.9.0-beta.2","v6.9.0-beta.1","v6.8.0","v6.8.0-beta.2","v6.8.0-beta.1","v6.7.1","v6.7.0-beta.3","v6.7.0-beta.2","v6.7.0-beta.1","v6.6.1","v6.6.0","v6.6.0-beta.1","v6.5.2","v6.5.1","v6.5.0","v6.4.3","v6.4.2","v6.4.1","v6.4.1-beta.1-placeholder"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55576.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}]}