Skip to main content
HIGH

CVE-2026-27938

CVSS v3

7.7

HIGH

EPSS Score

1.4 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from `develop` to `master` is merged, the PR body is injected verbatim into a shell command, allowing arbitrary command execution on the Actions runner. Version 2.9.1 contains a fix for

Technical details

Published
2026-02-26
Last Modified
2026-04-14

Frequently asked questions

What is CVE-2026-27938?

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from `develop` to `master` is merged, the PR body is injected verbatim into a shell command, allowing arbitrary command execution on the Actions runner. Version 2.9.1 contains a fix for

Is CVE-2026-27938 actively exploited?

Active exploitation of CVE-2026-27938 has not been confirmed. Its EPSS score was 1.4% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-27938?

CVE-2026-27938 has a CVSS v3 base score of 7.7 (HIGH severity).

Is CVE-2026-27938 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key