Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 21 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
Description Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.
Title Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-21T01:19:47.510Z

Reserved: 2026-04-07T19:13:20.379Z

Link: CVE-2026-39866

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T02:16:06.807

Modified: 2026-04-21T02:16:06.807

Link: CVE-2026-39866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses