GitHub Actions vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-PHF6-HM3H-X8QPCriticalbroadinstitute/cromwell: Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`CVE-2025-47775Mediumbullfrogsec/bullfrog: Bullfrog's DNS over TCP bypasses domain filteringCVE-2025-47271MediumOZI-Project/publish: OZI-Project/ozi-publish Code Injection vulnerabilityCVE-2025-32955Mediumstep-security/harden-runner: Harden-Runner allows evasion of 'disable-sudo' policyCVE-2025-31479Highcanonical/get-workflow-version-action: canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputCVE-2025-30154Highreviewdog/action-setup: Multiple Reviewdog actions were compromised during a specific time periodCVE-2025-30066Hightj-actions/changed-files: tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.CVE-2025-24362Highgithub/codeql-action: GitHub PAT written to debug artifactsGHSA-5XR6-XHWW-33M4Highdawidd6/action-download-artifact: Artifact poisoning vulnerability in action-download-artifact v5 and earlierCVE-2024-52587Lowstep-security/harden-runner: Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`GHSA-CXWW-7G56-2VH6Highactions/download-artifact: @actions/download-artifact has an Arbitrary File Write via artifact extractionGHSA-7X29-QQMQ-V6QCHighultralytics/actions: GitHub Actions Script Injection in `ultralytics/actions`CVE-2024-42482Mediumfish-shop/syntax-check: fish-shop/syntax-check Improper Neutralization of DelimitersGHSA-7F32-HM4H-W77QMediumrlespinasse/github-slug-action: github-slug-action use of `set-env` Runner commands which are processed via stdoutCVE-2023-52137Hightj-actions/verify-changed-files: Potential Actions command injection in output filenames (GHSL-2023-275)CVE-2023-51664Hightj-actions/changed-files: tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)CVE-2023-50245Criticalafichet/openexr-viewer: memory overflow vulnerability in OpenEXR-viewerCVE-2023-49291Criticaltj-actions/branch-names: tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code InjectionGHSA-HW6R-G8GJ-2987Mediumhttps://github.com/pytorch/pytorch/.github/actions/filter-test-configs: Actions expression injection in `filter-test-configs` (`GHSL-2023-181`)CVE-2023-30853Highgradle/gradle-build-action: Data written to GitHub Actions Cache may expose secretsCVE-2023-30623Highembano1/wip: Arbitrary command injection in embano1/wip CVE-2023-27581Highrlespinasse/github-slug-action: github-slug-action vulnerable to arbitrary code executionCVE-2023-23939LowAzure/setup-kubectl: Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lowerCVE-2022-39321Highactions/runner: Docker Command Escaping in the GitHub Actions RunnerCVE-2022-39326Highkartverket/github-workflows: run-terraform allows for RCE via terraform plan

Stop the waste.
Protect your environment with Kodem.