Description

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml, the prep job uses peter-evans/find-comment to search for an existing comment indicating that a docs issue has already been opened. The output steps.issue_comment.outputs.comment-body is then interpolated directly into a bash if statement. Because comment-body is attacker-controlled text and is inserted into shell syntax without escaping, a malicious comment body can break out of the quoted string and inject arbitrary shell commands. This vulnerability is fixed with commit bbed8d28354e9c644c5a7df13946a3a0451f9ab9.

INFO

Published Date :

2026-04-07T19:56:15.251Z

Last Modified :

2026-04-08T16:14:59.745Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-39382 vulnerability.

Vendors Products
Dbt-labs
  • Dbt-core
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-39382.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability