#VU125044 Command injection in emissary - CVE-2026-35580
Published: April 7, 2026
emissary
National Security Agency
Description
The vulnerability allows a remote user to execute arbitrary code and compromise the software supply chain.
The vulnerability exists due to command injection in GitHub Actions workflow files when processing user-controlled workflow_dispatch inputs in run blocks. A remote privileged user can supply crafted workflow inputs to execute arbitrary code and compromise the software supply chain.
Exploitation occurs within the CI/CD runner and may allow access to the job's GITHUB_TOKEN permissions and secrets from the GitHub Actions environment.