CVE-2026-34041 is a critical vulnerability affecting versions of the 'act' project prior to 0.2.86, which allows local execution of GitHub Actions. It enables environment injection by unconditionally processing deprecated workflow commands like ::set-env:: and ::add-path:: when untrusted data is echoed to stdout. This allows an attacker to set arbitrary environment variables or modify the PATH, posing a severe risk with a CVSS score of 9.8 (Critical). The vulnerability has a network-based, low-complexity attack vector, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code or community discussion, its "Hot List: Active" status indicates a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.86CPE matchmatch criteria | cpe:2.3:a:nektos:act:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.