THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2qvg-qr73-mqxp (critical) — conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target

[GHSA] GHSA-2qvg-qr73-mqxp (critical) — conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target

medgithub_advisoriesPublished 2026-08-17

GHSA-2qvg-qr73-mqxp Severity: critical CVE: CVE-2026-55158

conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target

### Impact

Versions of conflibot before `1.2.1` build `git` commands by string interpolation and run them through a shell. Several of the interpolated values are pull request branch names (`head.ref`), which are attacker-controlled:

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2qvg-qr73-mqxp