Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-34243

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-34243
  • Njzjz » Wenxian » Version: Any
    cpe:2.3:a:njzjz:wenxian:*


Contact Us

Shodan ® - All rights reserved