Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Datosh

#25319of 56,326
9.9Total CVSS
Vulnerabilities · 1
PT-2026-43300
9.9
2026-05-26
Unknown · Vowpal Wabbit · CVE-2026-44723
**Name of the Vulnerable Software and Affected Versions** Vowpal Wabbit (affected versions not specified) **Description** The workflow `.github/workflows/python checks.yml` embeds the `github.event.pull request.title` variable directly inside double-quoted bash strings across four separate steps and jobs. This variable is passed as a CLI argument to the `run tests model gen and load.py` Python test script. Because the shell interprets the expanded string before invoking Python, an attacker can break out of the quotes to execute arbitrary commands on the runner. The `pull request` trigger is active for PRs targeting any branch without additional access gates. **Recommendations** Apply the fix provided in commit 998e390e80a7e8192d7849b7784bc113dbd190ad.