CVE-2026-44246: Prompt injection in nnU-Net GitHub issue-triage agent workflow
Prior to version 2.4.1, nnU-Net's GitHub Actions issue-triage workflow embedded untrusted issue titles and bodies directly into the prompt of a command-capable Claude Code agent, allowing any GitHub user who opens an issue to steer the agent beyond its intended triage purpose and influence authenticated issue actions such as commenting and relabelling. The issue is fixed in nnU-Net 2.4.1.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
An external attacker could submit a crafted issue to trigger the automated agent and influence authenticated issue actions (commenting and relabelling) in the repository.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44246
