PT-2026-106219 · Chainguard Academy · Integrate-Platform-Docs

·

CVE-2026-105767

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

3.3

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chainguard Academy (edu) integrate-platform-docs composite GitHub Action versions from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff through commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3
Description Improper neutralization of special elements used in an OS command allows an actor who controls the project id or storage bucket inputs to execute arbitrary shell commands on the GitHub Actions runner. This occurs because these inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions.
Recommendations Update the integrate-platform-docs composite GitHub Action to commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105767

Affected Products

Integrate-Platform-Docs