CVE-2026-34041: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34041 is an environment injection vulnerability in nektos/act, a tool for running GitHub Actions workflows locally. The flaw arises because act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands — commands that GitHub Actions itself disabled in October 2020 (CVE-2020-15228) due to identical injection risks. All versions up to and including 0.2.85 are affected; version 0.2.86 contains the fix. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, act Security Advisory).

Technical details

The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). In pkg/runner/command.go (lines 52–58), the commandHandler function processes set-env and add-path workflow commands without checking for the ACTIONS_ALLOW_UNSECURE_COMMANDS environment variable, which GitHub Actions requires to be set to true before honoring these deprecated commands. An attacker who can influence data that a workflow step echoes to stdout — such as a PR title, branch name, or commit message — can embed ::set-env name=VAR::VALUE or ::add-path::/malicious/dir directives. Once processed, these directives persist for all subsequent steps in the job, enabling injection of dangerous variables like LD_PRELOAD, NODE_OPTIONS, PYTHONPATH, BASH_ENV, and PERL5OPT, or prepending attacker-controlled directories to PATH (GitHub Advisory, act Security Advisory).

Impact

Successful exploitation allows an unauthenticated network attacker to achieve arbitrary code execution with the privileges of the user running act on the developer's local machine. All three CIA pillars are fully compromised: confidentiality (secrets, credentials, source code accessible to the injected process), integrity (arbitrary code can modify files, tamper with build artifacts, or alter the supply chain), and availability (the local build environment can be disrupted or backdoored). A particularly dangerous supply chain risk exists because workflows that are safe when executed on GitHub Actions become exploitable when run locally with act, giving developers a false sense of security (GitHub Advisory).

Exploitability

A detailed proof-of-concept exploit is publicly available in the GitHub Security Advisory, including a complete malicious event.json payload and step-by-step reproduction instructions; Feedly classifies this as a confirmed real exploit with high confidence (act Security Advisory). The vulnerability was reported by researcher golang-not-rust and disclosed on March 25, 2026. The EPSS score is approximately 0.028% (9th percentile), indicating low current exploitation probability in the wild, and there is no evidence of active in-the-wild exploitation or CISA KEV listing at this time (GitHub Advisory). Qualys has assigned detection ID 761935 for this vulnerability.

Exploitation steps

  1. Reconnaissance: Identify developer environments or CI pipelines where nektos/act version ≤ 0.2.85 is used to run GitHub Actions workflows locally.
  2. Craft a malicious event payload: Create an event.json file with attacker-controlled fields (e.g., PR title) containing embedded ::set-env:: and ::add-path:: directives separated by newlines:
{
  "pull_request": {
    "title": "Fix typo\n::set-env name=NODE_OPTIONS::--require=/tmp/evil.js\n::set-env name=LD_PRELOAD::/tmp/evil.so\n::add-path::/tmp/evil-bin",
    "number": 1,
    "head": {"ref": "fix-typo", "sha": "abc123"},
    "base": {"ref": "main", "sha": "def456"}
  }
}
  1. Trigger workflow execution: Run act pull_request -e event.json against a workflow that echoes attacker-controlled data (e.g., echo "Processing PR: ${{ github.event.pull_request.title }}"). Alternatively, use a malicious branch name (fix-typo%0A::set-env name=LD_PRELOAD::/tmp/evil.so) or a crafted commit message that appears in git log output.
  2. Environment injection fires: act processes the embedded ::set-env:: and ::add-path:: commands without restriction, silently setting NODE_OPTIONS, LD_PRELOAD, and prepending /tmp/evil-bin to PATH for all subsequent workflow steps.
  3. Achieve code execution: Subsequent steps that invoke Node.js will load /tmp/evil.js via NODE_OPTIONS; dynamically-linked binaries will load /tmp/evil.so via LD_PRELOAD; any command lookup will resolve to attacker-controlled binaries in /tmp/evil-bin — all executing with the privileges of the user running act (act Security Advisory).

Indicators of compromise

  • Logs: act output containing lines matching ⚙ ::set-env:: or ⚙ ::add-path:: when no legitimate workflow step explicitly sets these commands; unexpected environment variable assignments appearing in workflow step logs.
  • File System: Presence of unexpected shared libraries (e.g., /tmp/evil.so) or executables in world-writable directories (e.g., /tmp/evil-bin/); new or modified files in the act working directory or Docker container volumes.
  • Process: Child processes of the act runner or Docker containers with unusual environment variables set (LD_PRELOAD, NODE_OPTIONS pointing to /tmp/ paths, PYTHONPATH, BASH_ENV, PERL5OPT); unexpected outbound network connections from the build container.
  • Network: Outbound connections from the developer machine or build container to unknown external hosts initiated during or immediately after a workflow run triggered by external input (PR, branch name, commit message) (act Security Advisory).

Mitigation and workarounds

Upgrade nektos/act to version 0.2.86 or later, which adds a check requiring ACTIONS_ALLOW_UNSECURE_COMMANDS=true before processing ::set-env:: and ::add-path:: commands, matching GitHub Actions' behavior since October 2020 (act Release v0.2.86, Patch Commit). As an interim workaround, avoid running workflows locally with act that process untrusted external input (PR titles, branch names, commit messages, issue bodies). Never run workflows from untrusted repositories using act. If the deprecated commands are genuinely needed, explicitly set ACTIONS_ALLOW_UNSECURE_COMMANDS=true in the workflow environment and audit all data flows carefully.

Community reactions

The vulnerability was reported by researcher golang-not-rust and coordinated with maintainer cplee (Casey Lee) prior to disclosure on March 25, 2026. The advisory notes that this is a regression relative to GitHub Actions, which addressed the same class of vulnerability in October 2020 (CVE-2020-15228), highlighting that act lagged behind the upstream platform's security posture for over five years. An openSUSE security announcement was issued referencing the vulnerability in the context of govulncheck/vulndb updates (openSUSE Announce). No significant broader media coverage or threat actor attribution has been observed.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management