CVE Tools

Github-actions

8 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.

Github-actions CVEs per month

Dec 2023 to Sep 2025. Point at a month, or focus the strip and use the arrow keys.
Github-actions CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1240
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-0940

Products

The products that kept showing up in Github-actions's monthly top three, with their CVEs summed over those months.

  1. Sonarsource/sonarqube-scan-action21 month
  2. Afichet/openexr-viewer11 month
  3. J178/prek-action11 month
  4. Pypa/gh-action-pypi-publish11 month
  5. Tj-actions/branch-names11 month
  6. Tj-actions/changed-files11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Github-actions.

  1. GHSA-c3xh-98xp-6qhfgithubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow—
  2. GHSA-5wxr-w449-57cmSetup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions—
  3. GHSA-wpqr-6v78-jr5gGemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses—
  4. GHSA-6p2j-742g-835factions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow—
  5. GHSA-f67f-hcr6-94mfZen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow—
  6. CVE-2026-31976xygeni-action v5 tag poisoned with C2 backdoor9.8
  7. CVE-2026-31900Black's vulnerable version parsing leads to RCE in GitHub Action9.8
  8. GHSA-v53h-f6m7-xcgmBlack's vulnerable version parsing leads to RCE in GitHub Action—
  9. CVE-2026-26189Trivy Action has a script injection via sourced env file in composite action5.9
  10. CVE-2026-25761Command injection via crafted filenames in Super-linter Action8.8
  11. CVE-2026-25598Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)5.3
  12. GHSA-pwf7-47c3-mfhxj178/prek-action vulnerable to arbitrary code injection in composite action—
  13. CVE-2025-59844Argument injection vulnerability in SonarQube Scan Action—
  14. GHSA-vxmw-7h4f-hqxhPyPI publish GitHub Action vulnerable to injectable expression expansions in action steps—
  15. CVE-2025-58178Command Injection via sonarqube-scan-action GitHub Action7.8

The record

Peak rank
#175 in Dec 2023
Busiest month shown
Dec 2023, 4 CVEs
Months with a KEV entry
0 since Dec 2023
Monthly snapshots
2 since 2023
Github-actions's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store