CVE-2026-48547
KanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.yml
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the release.yml workflow. Attackers can have a malicious pull request merged to trigger the GitHub Actions runner with contents write permissions and access to GITHUB_TOKEN.
| CWE | CWE-78 |
| Vendor | lingdojo |
| Product | kana-dojo |
| Published | Jun 11, 2026 |
| Last Updated | Jun 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for lingdojo kana-dojo
Be the first to know when new high vulnerabilities affecting lingdojo kana-dojo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
lingdojo / kana-dojo
0 < 0.1.18
References
Credits
Katriel Moses VulnCheck