CVE-2026-31976Active Exploitation(xygeni / xygeni-action)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch xygeni xygeni-action systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmerged PRs. This commit remained in the repository's git object store, and any workflow referencing @v5 would fetch and execute it. This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing xygeni/xygeni-action@v5 during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arbitrary command execution on the CI runner for up to 180 seconds per workflow run.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xygeni-action

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
xygeni-action

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 103-1103-12
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-112
Active Exploitation1Disclosure1
2026-03-121
Active Exploitation1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    A critical 9.4 CVSS tag poisoning attack (CVE-2026-31976) hit the xygeni-action GitHub Action, injecting a C2 backdoor into CI/CD pipelines. Update now. https://securityonline.info/the-mutable-tag-trap-critical-9-4-cvss-attack-on-xygeni-github-action-exposes-ci-cd-pipelines/ https://t.co/KJ51n8Uiui

    Post summary

    CVE-2026-31976 is a critical tag‑poisoning flaw that has been exploited to inject a C2 backdoor into CI/CD pipelines via the xygeni-action GitHub Action, and users are urged to apply an update.

    01031475
    10.6K followersView on X
  • CVE@CVEnew
    Active Exploitation

    CVE-2026-31976 xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #4… https://www.cve.org/CVERecord?id=CVE-2026-31976

    Post summary

    An attacker used compromised credentials to submit malicious pull requests to the xygeni-action GitHub Action, demonstrating active exploitation of CVE‑2026‑31976.

    00000176
    56.6K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31976: xygeni-action v5 tag poisoned wi... Tag poisoning through compromised GitHub App creds bypassed branch protection—180 seconds of CI runner control per work... https://zerodaysignal.com/vulnerability/CVE-2026-31976 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-31976, detailing how tag poisoning through compromised GitHub App credentials can bypass branch protection and grant temporary CI runner control, but it offers no PoC, exploit, patch, or evidence of active exploitation.

    0000087
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxygenixygeni-action---

Explore more