CVE-2026-31976

CVE-2026-31976 is a critical-severity security vulnerability in xygeni/xygeni-action (actions), affecting versions >= 5, < 6.4.0. It is fixed in 6.4.0.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

xygeni-action v5 tag poisoned with C2 backdoor

Description

On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch.

However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmerged PRs. This commit remained in the repository's git object store, and any workflow referencing @v5 would fetch and execute it.

The malicious code, disguised as a "scanner version telemetry" step, operates as follows:

  1. Registers the CI runner with a C2 server at 91.214.78.178 (via security-verify.91.214.78.178.nip.io), transmitting hostname, username, and OS version.
  2. Polls the C2 server every 2–7 seconds for 180 seconds, receiving and executing arbitrary shell commands via eval.
  3. Compresses and base64-encodes command output before exfiltrating it back to the C2 server.

The implant runs silently in the background alongside the legitimate scan, suppresses all errors, skips TLS certificate verification, and uses randomized polling intervals to evade detection.

Workarounds

As an alternative to using the GitHub Action, you may install and run the Xygeni scanner directly via the CLI installation method documented at https://docs.xygeni.io/xygeni-scanner-cli/xygeni-cli-overview/xygeni-cli-installation. This bypasses the GitHub Action entirely and is not affected by this incident.

References

Impact

This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing xygeni/xygeni-action@v5 during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arbitrary command execution on the CI runner for up to 180 seconds per workflow run.

The severity is set to Critical based on the potential impact. However, several factors reduce the realized risk: the v5 tag was primarily referenced by Xygeni-owned and Xygeni-affiliated repositories; no external public repositories were found using the compromised tag (though usage in private repositories cannot be ruled out); the exposure window was approximately 6 days; and no confirmed exploitation of downstream users has been established to date.

Affected versions

xygeni/xygeni-action (>= 5, < 6.4.0)

Security releases

xygeni/xygeni-action → 6.4.0 (actions)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

The compromised v5 tag has been removed from the repository. Users should update their workflows to pin to the verified safe commit SHA corresponding to v6.4.0:

uses: xygeni/xygeni-action@13c6ed2797df7d85749864e2cbcf09c893f43b23 # v6.4.0

Workflows still referencing @v5 will fail with a reference not found error, as the tag no longer exists.

If your workflows ran with @v5 during the affected window, you should also:

  • Rotate all secrets that were available to the CI runner (repository secrets, environment secrets, deploy keys, cloud provider tokens).
  • Audit CI logs for outbound connections to 91.214.78.178 or DNS lookups for security-verify.91.214.78.178.nip.io.
  • Review recent releases and published artifacts for signs of tampering.

Frequently Asked Questions

  1. What is CVE-2026-31976? CVE-2026-31976 is a critical-severity security vulnerability in xygeni/xygeni-action (actions), affecting versions >= 5, < 6.4.0. It is fixed in 6.4.0.
  2. Which versions of xygeni/xygeni-action are affected by CVE-2026-31976? xygeni/xygeni-action (actions) versions >= 5, < 6.4.0 is affected.
  3. Is there a fix for CVE-2026-31976? Yes. CVE-2026-31976 is fixed in 6.4.0. Upgrade to this version or later.
  4. Is CVE-2026-31976 exploitable, and should I be worried? Whether CVE-2026-31976 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2026-31976 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  6. How do I fix CVE-2026-31976? Upgrade xygeni/xygeni-action to 6.4.0 or later.

Stop the waste.
Protect your environment with Kodem.