Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow

Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow

Published 30 Aug 2026Updated 30 Aug 20262 sources
CVSS 0.0 PoC CANDIDATE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.