Github-actions
8 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.
Github-actions CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-12 | 4 | 0 |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | 4 | 0 |
Products
The products that kept showing up in Github-actions's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Github-actions.
- GHSA-c3xh-98xp-6qhfgithubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow—
- GHSA-5wxr-w449-57cmSetup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions—
- GHSA-wpqr-6v78-jr5gGemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses—
- GHSA-6p2j-742g-835factions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow—
- GHSA-f67f-hcr6-94mfZen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow—
- CVE-2026-31976xygeni-action v5 tag poisoned with C2 backdoor9.8
- CVE-2026-31900Black's vulnerable version parsing leads to RCE in GitHub Action9.8
- GHSA-v53h-f6m7-xcgmBlack's vulnerable version parsing leads to RCE in GitHub Action—
- CVE-2026-26189Trivy Action has a script injection via sourced env file in composite action5.9
- CVE-2026-25761Command injection via crafted filenames in Super-linter Action8.8
- CVE-2026-25598Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)5.3
- GHSA-pwf7-47c3-mfhxj178/prek-action vulnerable to arbitrary code injection in composite action—
- CVE-2025-59844Argument injection vulnerability in SonarQube Scan Action—
- GHSA-vxmw-7h4f-hqxhPyPI publish GitHub Action vulnerable to injectable expression expansions in action steps—
- CVE-2025-58178Command Injection via sonarqube-scan-action GitHub Action7.8
The record
- Peak rank
- #175 in Dec 2023
- Busiest month shown
- Dec 2023, 4 CVEs
- Months with a KEV entry
- 0 since Dec 2023
- Monthly snapshots
- 2 since 2023