CVE-2026-54594

Source
https://cve.org/CVERecord?id=CVE-2026-54594
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54594.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54594
Aliases
  • GHSA-pq9c-3595-72jq
Published
2026-09-17T19:51:32Z
Modified
2026-09-20T11:30:38Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OmniBlocks: Spamming in Discussions tab possible via disc.yml
Details

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was already converted or otherwise suppressing duplicate runs. A user who creates one off-topic issue and repeatedly edits its description before conversion completes can therefore cause multiple discussions to be created for the same issue, producing discussion spam and additional moderation work. This issue is fixed with commit 627e0f0a16a7d74b09128106b57dd7e85d2545df.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-799"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54594.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "OmniBlocks"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/omniblocks/monorepo

Affected ranges

Type
GIT
Repo
https://github.com/omniblocks/monorepo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54594.json"