PT-2026-95094 · Unknown · Omniblocks

·

CVE-2026-54594

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OmniBlocks versions prior to June 6, 2026
Description The .github/workflows/disc.yml workflow triggers on issues opened and edited events. When an issue is classified as off-topic, it invokes the createDiscussion mutation. Because the system does not record if an issue has already been converted or suppress duplicate runs, a user can repeatedly edit an off-topic issue's description before the initial conversion finishes. This allows the creation of multiple discussions for a single issue, resulting in discussion spam and increased moderation effort.
Recommendations Update to the version containing commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54594
GHSA-PQ9C-3595-72JQ

Affected Products

Omniblocks