← Back to browse · API

CVE-2026-34243

Severity
CRITICAL
CVSS
9.8
EPSS
0.02172
Risk score
39.96
CISA KEV
No
PoC
No
Published
2026-03-31
Modified
2026-04-02
First seen
2026-08-05
Aliases
EUVD-2026-17522, GHSA-R4FJ-R33X-8V88
Products
njzjz:wenxian, njzjz:wenxian ≤ 0.3.1
Sources
nvd CVE-2026-34243
euvd EUVD-2026-17522

Description

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.

References