Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

Project Subscriptions

Vendors Products
Lawnchairlauncher Subscribe
Lawnchair Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Lawnchairlauncher
Lawnchairlauncher lawnchair
Vendors & Products Lawnchairlauncher
Lawnchairlauncher lawnchair

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
Description Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.
Title Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-21T19:49:12.997Z

Reserved: 2026-04-07T19:13:20.379Z

Link: CVE-2026-39866

cve-icon Vulnrichment

Updated: 2026-04-21T15:56:14.076Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-21T02:16:06.807

Modified: 2026-04-21T20:16:58.627

Link: CVE-2026-39866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T11:46:59Z

Weaknesses