CVE-2026-39382 | dbt-labs dbt-core Comment open-issue-in-repo.yml steps.issue_comment.outputs.comment- os command injection (GHSA-5jxf-vmqr-5g82)
A vulnerability, which was classified as critical, has been found in dbt-labs dbt-core. Affected is an unknown function of the file dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml of the component Comment Handler. The manipulation of the argument steps.issue_comment.outputs.comment- leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-39382. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.