📦

wenxian

Vendor: njzjz

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 2.78% Exploit Prob.
Latest CVE CVE-2026-34243 Mar 31

Security Vulnerability Index

Page 1 / 1
9.8 CVSS
CVE-2026-34243
RCE Exploit Found

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.

EPSS: 2.78%