PulsePatch.io@pulsepatchioDisclosure
The post announces a critical shell injection flaw (CVE‑2026‑35580) affecting Emissary in GitHub Actions, potentially allowing arbitrary command execution, and urges reviewers to check workflow input sanitization.
Vulert@vulert_officialPatch
CVE-2026-35580 is a shell injection vulnerability in GitHub Actions workflows; the post urges users to upgrade and apply the recommended fix, with no exploit details or active usage reported.
CVEFind.com@CveFindComPatch
The tweet announces a critical shell injection flaw in Emissary’s GitHub Actions workflow files and indicates that upgrading to version 8.39.0 or later resolves the issue.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE-2026-35580, noting a shell‑injection vulnerability in Emissary’s GitHub Actions workflows pre‑version 8.39.0, but provides no exploit code, mitigation, or evidence of active use.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑35580 affecting Emissary’s P2P workflow engine, highlighting shell injection vulnerabilities in GitHub Actions workflow files.
0day Signal@0dayPublishingDisclosure
The post announces a newly disclosed CVE-2026-35580 involving RCE via ${{}} injection in GitHub Actions, but does not provide PoC, exploitation tools, or evidence of active use.