๐Ÿ” CVE Alert

CVE-2026-58502

UNKNOWN 0.0

githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell command-substitution syntax can therefore execute commands on the GitHub Actions runner before the title is included in the Discord notification sent through DISCORD_WEBHOOK. Successful exploitation can manipulate or spoof trusted bot notifications and may expose the Discord webhook secret or other workflow environment data, depending on repository permissions. This issue is fixed by commit 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027.

CWE CWE-78
Vendor gouef
Product githubtoplanguages
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for gouef githubtoplanguages

Be the first to know when new unknown vulnerabilities affecting gouef githubtoplanguages are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gouef / githubtoplanguages
< 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gouef/githubtoplanguages/security/advisories/GHSA-c3xh-98xp-6qhf github.com: https://github.com/gouef/githubtoplanguages/commit/6bf9c3a9cb66c937b9047ca266b3d02f2bb11027