PT-2026-67288 · Github+1 · Github Actions+1

·

CVE-2026-67308

·

Published

2026-08-01

·

Updated

2026-08-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wazuh workflows versions prior to 44bf114
Description A shell injection issue exists in GitHub Actions where attackers can execute arbitrary commands by submitting pull requests containing crafted VERSION.json files. This occurs because shell metacharacters injected into environment variables are directly interpolated into run steps. This flaw allows for command execution and the exfiltration of sensitive secrets, such as GITHUB TOKEN and AWS credentials, specifically on self-hosted runners.
Recommendations Update Wazuh workflows to version 44bf114 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67308

Affected Products

Github Actions
Wazuh Workflows