CVE-2026-39866
Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml
- Published
- Apr 21, 2026
- Updated
- Apr 25, 2026
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 25, 2026
Primary CVSS
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLow · next 30 days
- Percentile
- 82.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.
Sources
2- gha-lab-360f77d0d4Research
Reproduces CVE-2026-39866, a workflow_dispatch input template injection in a GitHub Actions workflow, using a pinned snapshot of the vulnerable commit for authorized security research.
Proof-of-concept lab demonstrating command injection in GitHub Actions workflow dispatch (CVE-2026-39866). Runs vulnerable and patched versions side-by-side for educational analysis.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.