github-actions
Latest CVEs
The 15 most recently published vulnerabilities affecting github-actions.
- GHSA-c3xh-98xp-6qhfgithubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
- GHSA-5wxr-w449-57cmSetup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions
- GHSA-wpqr-6v78-jr5gGemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
- GHSA-6p2j-742g-835factions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow
- GHSA-f67f-hcr6-94mfZen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow
- CVE-2026-31976xygeni-action v5 tag poisoned with C2 backdoor9.8
- CVE-2026-31900Black's vulnerable version parsing leads to RCE in GitHub Action9.8
- GHSA-v53h-f6m7-xcgmBlack's vulnerable version parsing leads to RCE in GitHub Action
- CVE-2026-26189Trivy Action has a script injection via sourced env file in composite action5.9
- CVE-2026-25761Command injection via crafted filenames in Super-linter Action8.8
- CVE-2026-25598Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)5.3
- GHSA-pwf7-47c3-mfhxj178/prek-action vulnerable to arbitrary code injection in composite action
- CVE-2025-59844Argument injection vulnerability in SonarQube Scan Action
- GHSA-vxmw-7h4f-hqxhPyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
- CVE-2025-58178Command Injection via sonarqube-scan-action GitHub Action7.8