Vulnerability Description
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork PR whose title starts with Release v could execute shell commands on the ubuntu-latest runner during the generate-changelog job. This vulnerability is fixed by commit cafc3946059e6337d2089d4fec8b6885ba17c332.
Related Weaknesses (CWE)
References
- https://github.com/MaaAssistantArknights/MaaAssistantArknights/commit/cafc394605
- https://github.com/MaaAssistantArknights/MaaAssistantArknights/security/advisori
FAQ
What is CVE-2026-55576?
CVE-2026-55576 is a documented vulnerability. MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.tit...
How severe is CVE-2026-55576?
CVSS scoring is not yet available for CVE-2026-55576. Check NVD for updates.
Is there a patch for CVE-2026-55576?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.