Remote Command Execution Vulnerability in JS Recon Tool by JS Recon
CVE-2026-55378

9.3CRITICAL

Key Information:

Vendor

Shriyanss

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55378?

The JS Recon tool, ranging from versions 1.2.1-beta.1 to 1.3.1-beta.2, has a vulnerability that allows remote users to execute commands through crafted pull request branch or fork names. This occurs due to the improper handling of untrusted variables in the PR Branch Checker workflow, enabling potential malicious users to exploit the GitHub Actions environment with elevated permissions using the GITHUB_TOKEN.

Affected Version(s)

js-recon >= 1.2.1-beta.1, < 1.3.1-beta.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.