PT-2026-95094 · Unknown · Omniblocks
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OmniBlocks versions prior to June 6, 2026
Description
The
.github/workflows/disc.yml workflow triggers on issues opened and edited events. When an issue is classified as off-topic, it invokes the createDiscussion mutation. Because the system does not record if an issue has already been converted or suppress duplicate runs, a user can repeatedly edit an off-topic issue's description before the initial conversion finishes. This allows the creation of multiple discussions for a single issue, resulting in discussion spam and increased moderation effort.Recommendations
Update to the version containing commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omniblocks