CVE-2026-34243Disclosure(njzjz / wenxian)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch njzjz wenxian systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wenxian

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-31); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
wenxian

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-30: 1Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 303-3003-3104-01
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-313
Disclosure3
2026-04-011
General1
Full discourse5 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34162 | CVSS 10.0 🔴 CVE-2026-34156 | CVSS 9.9 🔴 CVE-2026-34243 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet simply lists three high‑scoring CVEs with their CVSS scores and links to a general vulnerabilities page, offering no additional technical or operational details.

    0000028
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34243: CRITICAL] Vulnerability in Wenxian tool (v0.3.1 and prior) allows code execution via GitHub Actions workflow due to untrusted user input. No patches available at this time.#cve,CVE-2026-34243,#cybersecurity https://cvefind.com/CVE-2026-34243

    Post summary

    The post announces CVE‑2026‑34243 as a critical RCE vulnerability in Wenxian tool and notes that no patch exists yet.

    0000035
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34243 - Critical wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input f... https://www.thehackerwire.com/vulnerability/CVE-2026-34243/ https://t.co/Bv3eVmBkbh

    Post summary

    The post announces the CVE‑2026‑34243 as a critical flaw in wenxian’s GitHub Actions workflow that processes untrusted input, with links for further details.

    0000042
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34243: wenxian: Command Injection in Gi... GitHub Actions runners become RCE playgrounds when devs pipe issue comments straight to shell - trivial to pop with cra... https://zerodaysignal.com/vulnerability/CVE-2026-34243 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new command injection flaw in GitHub Actions runners that could lead to remote code execution, though no exploit code, patch, or evidence of active exploitation is provided.

    0000059
    194 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical njzjz/wenxian flaw CVE-2026-34243 is a command injection vulnerability that can be exploited through untrusted input in GitHub Actions workflows. 🔗 https://vulert.com/vuln-db/CVE-2026-34243 #CyberSecurity #GitHubActions #CommandInjection #CVE202634243 #AppSec #DevSecOps https://t.co/3ERgyNv78P

    Post summary

    The tweet announces the CVE‑2026‑34243 command injection flaw in GitHub Actions, linking to a database entry but providing no proof‑of‑concept, exploit code, or patch details.

    0000045
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnjzjzwenxian-python-

Explore more