Remote Command Execution Vulnerability in JS Recon Tool by JS Recon
CVE-2026-55378
9.3CRITICAL
What is CVE-2026-55378?
The JS Recon tool, ranging from versions 1.2.1-beta.1 to 1.3.1-beta.2, has a vulnerability that allows remote users to execute commands through crafted pull request branch or fork names. This occurs due to the improper handling of untrusted variables in the PR Branch Checker workflow, enabling potential malicious users to exploit the GitHub Actions environment with elevated permissions using the GITHUB_TOKEN.
Affected Version(s)
js-recon >= 1.2.1-beta.1, < 1.3.1-beta.2
