Shell Injection Vulnerability in dbt-Labs Product
CVE-2026-39382
9.3CRITICAL
What is CVE-2026-39382?
A shell injection vulnerability exists in dbt-Labs' reusable workflow for managing issues. The workflow allows user-controlled comments to be interpolated directly into shell commands. This could permit attackers to craft malicious comments that inject arbitrary shell commands into the system, potentially leading to unauthorized command execution within the environment. To ensure protection, users should update to the patched version based on commit bbed8d28354e9c644c5a7df13946a3a0451f9ab9.
Affected Version(s)
dbt-core < bbed8d28354e9c644c5a7df13946a3a0451f9ab9
