CVE-2026-35580Disclosure(nsa / emissary)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nsa emissary systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • emissary

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-07); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
emissary

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-07: 4Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-07: 4Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 104-0704-0804-09
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-074
Disclosure3Patch1
2026-04-081
Patch1
2026-04-091
Disclosure1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical shell injection vulnerability (CVE-2026-35580) affects `Emissary` within `GitHub Actions` workflows, enabling potential arbitrary command execution. Review workflow input sanitization. #GitHubActions #AppSec #CVE https://www.pulsepatch.io/posts/cve-2026-35580-emissary-github-actions-shell-injection

    Post summary

    The post announces a critical shell injection flaw (CVE‑2026‑35580) affecting Emissary in GitHub Actions, potentially allowing arbitrary command execution, and urges reviewers to check workflow input sanitization.

    1001072
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical Emissary flaw: CVE-2026-35580 A shell injection issue in GitHub Actions workflows could put applications at risk. Upgrade now and apply the recommended fix. 🔗 https://vulert.com/vuln-db/CVE-2026-35580 #CyberSecurity #Emissary #CVE202635580 #Vulert https://t.co/AjF39Ap8L7

    Post summary

    CVE-2026-35580 is a shell injection vulnerability in GitHub Actions workflows; the post urges users to upgrade and apply the recommended fix, with no exploit details or active usage reported.

    0000045
    124 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35580: CRITICAL] Vulnerability in Emissary's GitHub Actions workflow files prior to 8.39.0 allowed for shell injection. Ensure you're using version 8.39.0 or higher to fix this issue.#cve,CVE-2026-35580,#cybersecurity https://cvefind.com/CVE-2026-35580

    Post summary

    The tweet announces a critical shell injection flaw in Emissary’s GitHub Actions workflow files and indicates that upgrading to version 8.39.0 or later resolves the issue.

    0000036
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35580 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_di… https://www.cve.org/CVERecord?id=CVE-2026-35580 ----- Traducción: CVE-2026-35580 Emi… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-35580, noting a shell‑injection vulnerability in Emissary’s GitHub Actions workflows pre‑version 8.39.0, but provides no exploit code, mitigation, or evidence of active use.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35580 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_di… https://www.cve.org/CVERecord?id=CVE-2026-35580

    Post summary

    The text announces CVE‑2026‑35580 affecting Emissary’s P2P workflow engine, highlighting shell injection vulnerabilities in GitHub Actions workflow files.

    00000222
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35580: Emissary has GitHub Actions Shel... NSA's Emissary P2P workflow engine lets repo contributors RCE via ${{}} injection in GitHub Actions - supply chain nigh... https://zerodaysignal.com/vulnerability/CVE-2026-35580 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a newly disclosed CVE-2026-35580 involving RCE via ${{}} injection in GitHub Actions, but does not provide PoC, exploitation tools, or evidence of active use.

    0000057
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnsaemissary---

Explore more