
A critical 9.4 CVSS tag poisoning attack (CVE-2026-31976) hit the xygeni-action GitHub Action, injecting a C2 backdoor into CI/CD pipelines. Update now. https://securityonline.info/the-mutable-tag-trap-critical-9-4-cvss-attack-on-xygeni-github-action-exposes-ci-cd-pipelines/ https://t.co/KJ51n8Uiui
Post summary
CVE-2026-31976 is a critical tag‑poisoning flaw that has been exploited to inject a C2 backdoor into CI/CD pipelines via the xygeni-action GitHub Action, and users are urged to apply an update.


