Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35580

31
FAUCET Score

CVE-2026-35580 is a critical shell injection vulnerability in Emissary (a P2P-based workflow engine) versions prior to 8.39.0, where GitHub Actions workflow files fail to properly sanitize user-controlled workflow_dispatch inputs, allowing them to be directly interpolated into shell commands. An attacker with repository write access can inject arbitrary shell commands to compromise the repository and potentially affect all downstream users through supply chain attacks. The vulnerability carries a CVSS severity score of 9.1 (CRITICAL) with a network attack vector, low attack complexity, and high privilege requirements. The impact is severe, affecting confidentiality, integrity, and availability across multiple systems due to the supply chain implications of workflow poisoning. Currently, this vulnerability shows no active exploitation in the wild, with no known public exploit code available. It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists, though the FAUCET risk score of 52.0/100 warrants monitoring as threat landscape dynamics evolve.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.10.0, <= 8.38.0CPE matchmatch criteria
cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 32nd percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: gov.nsa.emissary:emissaryFixed in: 8.39.0

Vendor Advisories (1)

mavenGHSA-3g6g-gq4r-xjm9critical

Emissary has GitHub Actions Shell Injection via Workflow Inputs

Apr 8, 2026

References

github.com / NationalSecurityAgency/emissary/pull/1286
Patch
github.com / NationalSecurityAgency/emissary/pull/1288
Patch
github.com / NationalSecurityAgency/emissary/security/advisories/GHSA-3g6g-gq4r-xjm9
ExploitVendor Advisory