
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34041 is an environment injection vulnerability in nektos/act, a tool for running GitHub Actions workflows locally. The flaw arises because act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands — commands that GitHub Actions itself disabled in October 2020 (CVE-2020-15228) due to identical injection risks. All versions up to and including 0.2.85 are affected; version 0.2.86 contains the fix. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, act Security Advisory).
The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). In pkg/runner/command.go (lines 52–58), the commandHandler function processes set-env and add-path workflow commands without checking for the ACTIONS_ALLOW_UNSECURE_COMMANDS environment variable, which GitHub Actions requires to be set to true before honoring these deprecated commands. An attacker who can influence data that a workflow step echoes to stdout — such as a PR title, branch name, or commit message — can embed ::set-env name=VAR::VALUE or ::add-path::/malicious/dir directives. Once processed, these directives persist for all subsequent steps in the job, enabling injection of dangerous variables like LD_PRELOAD, NODE_OPTIONS, PYTHONPATH, BASH_ENV, and PERL5OPT, or prepending attacker-controlled directories to PATH (GitHub Advisory, act Security Advisory).
Successful exploitation allows an unauthenticated network attacker to achieve arbitrary code execution with the privileges of the user running act on the developer's local machine. All three CIA pillars are fully compromised: confidentiality (secrets, credentials, source code accessible to the injected process), integrity (arbitrary code can modify files, tamper with build artifacts, or alter the supply chain), and availability (the local build environment can be disrupted or backdoored). A particularly dangerous supply chain risk exists because workflows that are safe when executed on GitHub Actions become exploitable when run locally with act, giving developers a false sense of security (GitHub Advisory).
A detailed proof-of-concept exploit is publicly available in the GitHub Security Advisory, including a complete malicious event.json payload and step-by-step reproduction instructions; Feedly classifies this as a confirmed real exploit with high confidence (act Security Advisory). The vulnerability was reported by researcher golang-not-rust and disclosed on March 25, 2026. The EPSS score is approximately 0.028% (9th percentile), indicating low current exploitation probability in the wild, and there is no evidence of active in-the-wild exploitation or CISA KEV listing at this time (GitHub Advisory). Qualys has assigned detection ID 761935 for this vulnerability.
nektos/act version ≤ 0.2.85 is used to run GitHub Actions workflows locally.event.json file with attacker-controlled fields (e.g., PR title) containing embedded ::set-env:: and ::add-path:: directives separated by newlines:{
"pull_request": {
"title": "Fix typo\n::set-env name=NODE_OPTIONS::--require=/tmp/evil.js\n::set-env name=LD_PRELOAD::/tmp/evil.so\n::add-path::/tmp/evil-bin",
"number": 1,
"head": {"ref": "fix-typo", "sha": "abc123"},
"base": {"ref": "main", "sha": "def456"}
}
}act pull_request -e event.json against a workflow that echoes attacker-controlled data (e.g., echo "Processing PR: ${{ github.event.pull_request.title }}"). Alternatively, use a malicious branch name (fix-typo%0A::set-env name=LD_PRELOAD::/tmp/evil.so) or a crafted commit message that appears in git log output.act processes the embedded ::set-env:: and ::add-path:: commands without restriction, silently setting NODE_OPTIONS, LD_PRELOAD, and prepending /tmp/evil-bin to PATH for all subsequent workflow steps./tmp/evil.js via NODE_OPTIONS; dynamically-linked binaries will load /tmp/evil.so via LD_PRELOAD; any command lookup will resolve to attacker-controlled binaries in /tmp/evil-bin — all executing with the privileges of the user running act (act Security Advisory).act output containing lines matching ⚙ ::set-env:: or ⚙ ::add-path:: when no legitimate workflow step explicitly sets these commands; unexpected environment variable assignments appearing in workflow step logs./tmp/evil.so) or executables in world-writable directories (e.g., /tmp/evil-bin/); new or modified files in the act working directory or Docker container volumes.act runner or Docker containers with unusual environment variables set (LD_PRELOAD, NODE_OPTIONS pointing to /tmp/ paths, PYTHONPATH, BASH_ENV, PERL5OPT); unexpected outbound network connections from the build container.Upgrade nektos/act to version 0.2.86 or later, which adds a check requiring ACTIONS_ALLOW_UNSECURE_COMMANDS=true before processing ::set-env:: and ::add-path:: commands, matching GitHub Actions' behavior since October 2020 (act Release v0.2.86, Patch Commit). As an interim workaround, avoid running workflows locally with act that process untrusted external input (PR titles, branch names, commit messages, issue bodies). Never run workflows from untrusted repositories using act. If the deprecated commands are genuinely needed, explicitly set ACTIONS_ALLOW_UNSECURE_COMMANDS=true in the workflow environment and audit all data flows carefully.
The vulnerability was reported by researcher golang-not-rust and coordinated with maintainer cplee (Casey Lee) prior to disclosure on March 25, 2026. The advisory notes that this is a regression relative to GitHub Actions, which addressed the same class of vulnerability in October 2020 (CVE-2020-15228), highlighting that act lagged behind the upstream platform's security posture for over five years. An openSUSE security announcement was issued referencing the vulnerability in the context of govulncheck/vulndb updates (openSUSE Announce). No significant broader media coverage or threat actor attribution has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."