Sploitus

CVE-2026-54344

No indexed exploits for CVE-2026-54344 yet

ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open pull request with a deploy command to execute shell commands on the CI runner and exfiltrate deployment secrets. This issue is reported as fixed in version 3.20.180.

Affected products
Tooljet
Fix
Available
CVSS 3.1
4.7 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-78
NVD status
Awaiting Analysis
Published
2026-07-08
CVE-2026-54344 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-54344 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-54344 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.