logo

CVE-2026-55158: Conflibot Command Injection via Pull Request Branch Name

ID: 6a653139-ebf6-590f-87f6-f8e633fcdcb2

STIX ID: report--6a653139-ebf6-590f-87f6-f8e633fcdcb2

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

...
...

Conflibot (pre-1.2.1) contains a critical command-injection vulnerability (CVE-2026-55158, CVSS 9.1) that interpolates attacker-controlled pull-request branch names into shell-executed git commands; when run on the privileged pull_request_target event this allows unauthenticated contributors to execute arbitrary commands in the base-repository runner, enabling secret exfiltration, unauthorized pushes, and supply-chain compromise. Immediate mitigation is upgrading to 1.2.1+ (or 2.0.0+), rotating exposed secrets, and auditing recent PR activity and workflow runs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.