CVE Explorer
CVE-2026-31976
xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmer
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xygeni-action","vendor":"xygeni","versions":[{"status":"affected","version":">= March 3, 2026, <= March 10, 2026"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f64f42ac4ad6a67cd073d18da1644e3e1eef08d2cc82b93007f63bc81153fcf5 · sha256:3b56b4a7aa02bcac… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f64f42ac4ad6a67cd073d18da1644e3e1eef08d2cc82b93007f63bc81153fcf5 · sha256:3b56b4a7aa02bcac… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-506","description":"CWE-506: Embedded Malicious Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f64f42ac4ad6a67cd073d18da1644e3e1eef08d2cc82b93007f63bc81153fcf5 · sha256:3b56b4a7aa02bcac… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/xygeni/xygeni-action/issues/54","tags":["x_refsource_MISC"],"url":"https://github.com/xygeni/xygeni-action/issues/54"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f64f42ac4ad6a67cd073d18da1644e3e1eef08d2cc82b93007f63bc81153fcf5 · sha256:3b56b4a7aa02bcac… · /containers/cna/references/1
{"name":"https://github.com/xygeni/xygeni-action/security/advisories/GHSA-f8q5-h5qh-33mh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/xygeni/xygeni-action/security/advisories/GHSA-f8q5-h5qh-33mh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f64f42ac4ad6a67cd073d18da1644e3e1eef08d2cc82b93007f63bc81153fcf5 · sha256:3b56b4a7aa02bcac… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.