CVE Explorer
CVE-2026-54344
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open pull request with a deploy command to execute shell commands on the CI runner and exfiltrate deployment secrets. This issue is reported as fixed in version 3.20.180.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"ToolJet","vendor":"ToolJet","versions":[{"status":"affected","version":"< 3.20.180"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:14b94d8d6b7d76b08c798693e4db32dc8f84311bec5a370abbc9948a707f1436 · sha256:fc577f154a217f92… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:14b94d8d6b7d76b08c798693e4db32dc8f84311bec5a370abbc9948a707f1436 · sha256:fc577f154a217f92… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:14b94d8d6b7d76b08c798693e4db32dc8f84311bec5a370abbc9948a707f1436 · sha256:fc577f154a217f92… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14b94d8d6b7d76b08c798693e4db32dc8f84311bec5a370abbc9948a707f1436 · sha256:fc577f154a217f92… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14b94d8d6b7d76b08c798693e4db32dc8f84311bec5a370abbc9948a707f1436 · sha256:fc577f154a217f92… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.