« Back to list

Github

Github Actions: vulnerabilities and CVEs

Github Actions has 9 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-58502High (7.1)0.53%—Sep 15, 2026
githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the…
CVE-2026-82856Critical (9.3)0.51%—Aug 31, 2026
@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub…
CVE-2026-24059Medium (6.5)0.41%—Aug 13, 2026
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as…
CVE-2024-58354High (8.5)0.56%—Jul 23, 2026
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's…
CVE-2026-55576High (8.8)0.46%—Jul 15, 2026
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run:…
CVE-2026-48547High (8.5)1.4%—Jun 11, 2026
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of…
CVE-2026-45132Critical (10)0.44%—Jun 1, 2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to…
CVE-2026-45131Critical (10)0.44%—Jun 1, 2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged…
CVE-2026-44590Critical (9.3)1.3%—May 27, 2026
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1098 Account Manipulation1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Github