PT-2026-50562 · Github · Github Workflows

·

CVE-2026-12567

·

Published

2026-06-17

·

Updated

2026-07-13

CVSS v3.1

2.2

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions github workflows (affected versions not specified)
Description The github workflows module constructs local directory paths using repository names provided by the user without validating for symlinks. A local attacker with access to the scan directory can place a symlink at the predictable output path, which leads to workflow data being written to a location chosen by the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12567
GHSA-RVP7-W75Q-9FV2
PYSEC-2026-2394

Affected Products

Github Workflows