CVE-2026-34041Disclosure(nektos / act)

LOWCVSS 7.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands, which was disabled due to environment injection risks. When a workflow step echoes untrusted data to stdout, an attacker can inject these commands to set arbitrary environment variables or modify the PATH for all subsequent steps in the job. This issue has been patched in version 0.2.86.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • act

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
act

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-31: 303-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-34041 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34041 #CVE-2026-34041 #CVE #High #CyberSecurity #InfoSec https://t.co/ATnOu3lMQK

    Post summary

    This post announces the new CVE‑2026‑34041 with a severity score of 7.7 and links to the NVD entry, but provides no technical, exploit, or mitigation details.

    0000031
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34041 act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: … https://www.cve.org/CVERecord?id=CVE-2026-34041

    Post summary

    The post reports a CVE affecting the act tool, indicating that versions prior to 0.2.86 improperly handle deprecated GitHub Actions directives, but it provides no evidence of exploitation, PoC, or patch information.

    0000087
    56.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34041 act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env: https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34041

    Post summary

    The snippet reports CVE‑2026‑34041, noting that act versions prior to 0.2.86 process deprecated ::set-env, but provides no further technical or mitigation details.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnektosact---

Explore more