๐Ÿ” CVE Alert

CVE-2026-48547

HIGH 7.3

KanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.yml

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the release.yml workflow. Attackers can have a malicious pull request merged to trigger the GitHub Actions runner with contents write permissions and access to GITHUB_TOKEN.

CWE CWE-78
Vendor lingdojo
Product kana-dojo
Published Jun 11, 2026
Last Updated Jun 11, 2026
Stay Ahead of the Next One

Get instant alerts for lingdojo kana-dojo

Be the first to know when new high vulnerabilities affecting lingdojo kana-dojo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

lingdojo / kana-dojo
0 < 0.1.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lingdojo/kana-dojo/releases/tag/v0.1.18

Credits

Katriel Moses VulnCheck