
Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml — snapshot of njzjz/wenxian@ca4e04de86aa970c0e3cb1c7f2bd103d339fbe51
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
njzjz/wenxianat commitca4e04de86aa970c0e3cb1c7f2bd103d339fbe51(2026-02-15), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-02-15; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
wenxian is a tool to generate ${\mathrm{B{\scriptstyle{IB}} T_{\displaystyle E} X}}$ files from given identifiers (DOI, PMID, arXiv ID, or paper title).
子曰:“夏礼,吾能言之,杞不足征也。殷礼,吾能言之,宋不足征也。文献不足故也。足,则吾能征之矣。”——《论语》
[!CAUTION] Deprecated, as several websites that serve the API have disabled CORS.
Visit wenxian.njzjz.win to use wenxian in the browser.
wenxian requires Python 3.10. It's suggested to install uv first:
pip install uv
Then use uvx to run wenxian:
uvx wenxian from 10.1063/5.0155600
You can also search by paper title:
uvx wenxian from "Attention is all you need"
It is expected to see a ${\mathrm{B{\scriptstyle{IB}} T_{\displaystyle E} X}}$ entry printed into the standard output.
By default, wenxian outputs ${\mathrm{B{\scriptstyle{IB}} T_{\displaystyle E} X}}$ format. You can use the -t text or --type text option to generate plain text format.
wenxian provides an Agent Skill in the skill directory, which has been supported by
OpenClaw,
Claude,
Codex,
and VS Code.
For example, you can ask your OpenClaw bot to install the skill https://github.com/njzjz/wenxian/tree/master/skill.
After that is done, you can ask the bot to generate the references by sending the bot paper titles or DOIs.
You can use wenxian in a GitHub Actions workflow, as a bridge between the input identifiers and the output ${\mathrm{B{\scriptstyle{IB}} T_{\displaystyle E} X}}$ entries:
- name: Run wenxian
id: wenxian
uses: njzjz/wenxian@master
with:
id: 1512.03385
- name: Furthur uses (an example)
run: echo "${{ steps.wenxian.outputs.bibtex }}"
You can use wenxian in a GitHub issue of this repository.
Comment @njzjz-bot 2312.15492 in #23, and the GitHub Actions will reply with the output ${\mathrm{B{\scriptstyle{IB}} T_{\displaystyle E} X}}$ entries.