Nektos develops the Act workflow automation and orchestration platform, a narrowly scoped product line oriented toward security and DevOps pipeline integration. The durable signal in this vendor's disclosures centers on output-injection weaknesses, reflecting the parsing and template-handling complexity inherent to workflow engines that consume and process data across heterogeneous toolchains. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nektos over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34041CRITICAL act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow comma | Mar 31, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nektos.
Media articles that mention a CVE ID that affects a product developed by Nektos — matched by CVE ID, not by vendor name.