PatchSiren cyber security CVE debrief
CVE-2026-55158 wktk CVE debrief
CVE-2026-55158 Conflibot security advisory debrief. Conflibot, a tool for warning about merge conflicts in pull requests, had a critical vulnerability prior to version 1.2.1. The issue allowed for arbitrary command execution via shell metacharacters in pull request branch names, potentially leading to secret exfiltration, unauthorized pushes, and token abuse. DevOps teams and developers must assess their exposure and update to a fixed version to prevent potential security breaches. The vulnerability was addressed in versions 1.2.1 and 2.0.0 by changing how commands are executed and using numeric pull-request refs.
- Vendor
- wktk
- Product
- conflibot
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-29
Who should care
DevOps teams and developers using Conflibot in their workflows should assess their exposure and update to a fixed version to prevent potential security breaches. This includes reviewing current deployments, understanding the vulnerability's impact, and implementing necessary updates or mitigations. Security teams and vulnerability management teams should also review the affected scope and severity to ensure proper remediation and monitoring.
Why it matters
CVE-2026-55158 is a critical vulnerability in Conflibot that allows for arbitrary command execution, potentially leading to security breaches. DevOps teams and developers must assess their exposure and update to a fixed version.
- Arbitrary command execution on runners with base-repository secrets and write-scoped GITHUB_TOKEN
- Potential for secret or token exfiltration
- Unauthorized pushes and token abuse
- Need for verification of affected versions and remediation
Technical summary
Conflibot, a tool for warning about merge conflicts in pull requests, had a critical vulnerability prior to version 1.2.1. The issue allowed for arbitrary command execution via shell metacharacters in pull request branch names, potentially leading to secret exfiltration, unauthorized pushes, and token abuse. The vulnerability was addressed in versions 1.2.1 and 2.0.0 by changing how commands are executed and using numeric pull-request refs.
Defensive priority
High
Recommended defensive actions
- Review and update Conflibot to version 1.2.1 or 2.0.0
- Restrict pull request branch names to prevent shell metacharacters
- Monitor for suspicious activity in Conflibot workflows
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry detail a critical vulnerability in Conflibot versions prior to 1.2.1, allowing for arbitrary command execution via shell metacharacters in pull request branch names. The issue is fixed in versions 1.2.1 and 2.0.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55158 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55158
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55158 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55158
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/commit/0107ac6a4575ea200d0b92287ea58f975be9505d
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/commit/59e255c49c920fd6b67471ab9ef3bf194439a3f2
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/pull/329
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/releases/tag/v1.2.1
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/releases/tag/v2.0.0
-
Source reference
Unverified legacy reference
URL: https://github.com/wktk/conflibot/security/advisories/GHSA-2qvg-qr73-mqxp
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.