CVE-2026-35580 is a critical shell injection vulnerability in Emissary (a P2P-based workflow engine) versions prior to 8.39.0, where GitHub Actions workflow files fail to properly sanitize user-controlled workflow_dispatch inputs, allowing them to be directly interpolated into shell commands. An attacker with repository write access can inject arbitrary shell commands to compromise the repository and potentially affect all downstream users through supply chain attacks. The vulnerability carries a CVSS severity score of 9.1 (CRITICAL) with a network attack vector, low attack complexity, and high privilege requirements. The impact is severe, affecting confidentiality, integrity, and availability across multiple systems due to the supply chain implications of workflow poisoning. Currently, this vulnerability shows no active exploitation in the wild, with no known public exploit code available. It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists, though the FAUCET risk score of 52.0/100 warrants monitoring as threat landscape dynamics evolve.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.0, <= 8.38.0CPE matchmatch criteria | cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.