---
id: CVE-2026-55576
title: MaaAssistantArknights is a one-click tool for daily Arknights tasks
summary: >-
  MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the
  current dev-v2 workflow, .github/workflows/release-preparation.yml inlined
  attacker-controlled github.event.pull_request.title into a run: shell command
  during t…
severity: none
cwe:
  - CWE-78
  - CWE-94
published: '2026-07-15'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55576'
references:
  - url: >-
      https://github.com/MaaAssistantArknights/MaaAssistantArknights/commit/cafc3946059e6337d2089d4fec8b6885ba17c332
    label: security-advisories@github.com
  - url: >-
      https://github.com/MaaAssistantArknights/MaaAssistantArknights/security/advisories/GHSA-pqx2-5g66-f5w8
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00461
epssPercentile: 0.37333
ingestedAt: '2026-07-18T18:24:14.395Z'
---

## Overview

MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork PR whose title starts with Release v could execute shell commands on the ubuntu-latest runner during the generate-changelog job. This vulnerability is fixed by commit cafc3946059e6337d2089d4fec8b6885ba17c332.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
