CVE-2026-54344

ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open pull request with a deploy command to execute shell commands on the CI runner and exfiltrate deployment secrets. This issue is reported as fixed in version 3.20.180.
Configurations

No configuration.

History

08 Jul 2026, 17:17

Type Values Removed Values Added
References () https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm - () https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm -

08 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 16:16

Updated : 2026-07-09 19:40


NVD link : CVE-2026-54344

Mitre link : CVE-2026-54344

CVE.ORG link : CVE-2026-54344


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')