Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersPatch
A critical supply‑chain vulnerability (CVE‑2026‑31852) affecting Jellyfin iOS enables repo takeover and secret exfiltration via a GitHub Actions workflow; operators are advised to disable the workflow as a temporary mitigation while a patch is pending.
ExploitGrid@exploitgridExploit
The post announces a critical PoC for CVE‑2026‑31852 and provides a link to a functional exploit on ExploitGrid.
ExploitGrid@exploitgridGeneral
The post lists several CVEs without providing any additional technical, exploitation, or remediation details.
0day Signal@0dayPublishingExploit
CVE-2026-31852 exposes a GitHub Actions flaw that lets attackers fork an org’s PR and gain full write access, effectively stealing Apple App keys; the tweet indicates the vulnerability is actively being exploited with no patch discussed.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces the CVE‑2026‑31852 vulnerability, noting it enables arbitrary code execution via the Jellyfin iOS GitHub Actions workflow, with no evidence of a PoC, exploit, patch, or active exploitation.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑31852 affecting Jellyfin’s GitHub Actions workflow, indicating arbitrary code execution via pull requests, but does not provide PoC, exploit, patch, or active exploitation details.
CVEFind.com@CveFindComDisclosure
A critical (CVE-2026-31852) vulnerability in Jellyfin's GitHub Actions workflow, enabling code execution and repository takeover, has been disclosed.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-31852, noting that Jellyfin’s GitHub Actions workflow is vulnerable to arbitrary code execution via pull requests from forked repos, and points to a vulnerability report without mentioning a PoC, exploit, or patch.