THREAT OPS › Threat News › [GHSA] GHSA-2qvg-qr73-mqxp (critical) — conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
[GHSA] GHSA-2qvg-qr73-mqxp (critical) — conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
GHSA-2qvg-qr73-mqxp Severity: critical CVE: CVE-2026-55158
conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
### Impact
Versions of conflibot before `1.2.1` build `git` commands by string interpolation and run them through a shell. Several of the interpolated values are pull request branch names (`head.ref`), which are attacker-controlled:
Indicators of compromise
- CVE-2026-55158cve
Original source: https://github.com/advisories/GHSA-2qvg-qr73-mqxp