Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lawnchair
Lawnchair lawnchair |
|
| CPEs | cpe:2.3:a:lawnchair:lawnchair:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lawnchair
Lawnchair lawnchair |
|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lawnchairlauncher
Lawnchairlauncher lawnchair |
|
| Vendors & Products |
Lawnchairlauncher
Lawnchairlauncher lawnchair |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue. | |
| Title | Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-25T03:55:32.652Z
Reserved: 2026-04-07T19:13:20.379Z
Link: CVE-2026-39866
Updated: 2026-04-21T15:56:14.076Z
Status : Analyzed
Published: 2026-04-21T02:16:06.807
Modified: 2026-04-23T18:26:17.083
Link: CVE-2026-39866
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:46:59Z