Github
Github Actions: vulnerabilities and CVEs
Github Actions has 9 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months9
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58502 | High (7.1) | 0.53% | — | Sep 15, 2026 | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the… |
| CVE-2026-82856 | Critical (9.3) | 0.51% | — | Aug 31, 2026 | @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub… |
| CVE-2026-24059 | Medium (6.5) | 0.41% | — | Aug 13, 2026 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as… |
| CVE-2024-58354 | High (8.5) | 0.56% | — | Jul 23, 2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's… |
| CVE-2026-55576 | High (8.8) | 0.46% | — | Jul 15, 2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run:… |
| CVE-2026-48547 | High (8.5) | 1.4% | — | Jun 11, 2026 | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of… |
| CVE-2026-45132 | Critical (10) | 0.44% | — | Jun 1, 2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to… |
| CVE-2026-45131 | Critical (10) | 0.44% | — | Jun 1, 2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged… |
| CVE-2026-44590 | Critical (9.3) | 1.3% | — | May 27, 2026 | Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.