Skip to content
Threat Feed

Tag

Ci-Cd

7 briefs RSS
critical advisory

Wazuh GitHub Actions Shell Injection Vulnerability

A shell injection vulnerability in Wazuh workflows allows unauthenticated attackers to execute arbitrary commands and exfiltrate secrets via malicious pull requests containing crafted VERSION.json files.

Wazuh supply-chain ci-cd code-injection
3t 1c
critical advisory

Gitea Actions Fork Pull Request Approval Gate Bypass

A vulnerability in Gitea Actions (versions v1.20.0 and later) allows an unprivileged attacker to permanently bypass the fork pull request approval gate for a repository after a single, initial workflow approval, enabling arbitrary shell command execution on the Gitea Actions runner without further maintainer interaction, leading to source code disclosure and potential system compromise.

PoC Gitea +1 logic-bug ci-cd code-execution privilege-escalation gitea-actions
4t 1c 1i updated
critical advisory

Nuclio Java Runtime Vulnerability Leads to Build-Time Remote Code Execution

Nuclio's Java runtime dashboard API, by default configured with NOP authentication, is vulnerable to remote code execution (CWE-94) where attackers can inject arbitrary Groovy code into the unsanitized `runtimeAttributes.repositories` field, which is directly written into the `build.gradle` file, allowing the injected code to execute during the Gradle configuration phase as root within the build container.

Nuclio <= 1.15.27 code-injection rce template-injection kubernetes ci-cd groovy
1r 5t 1i
critical advisory

AsyncAPI npm Supply Chain Compromise via GitHub Actions

Threat actors compromised AsyncAPI npm packages by exploiting a misconfigured GitHub Actions workflow, stealing a privileged bot token, and injecting obfuscated Miasma malware into multiple packages, which then executed at module-load time to establish persistence and command and control, bypassing standard npm installation mitigations.

@asyncapi/generator@3.3.1 +4 supply-chain npm github-actions malware javascript nodejs ci-cd
2r 9t 3i
low advisory

Trivy Unbounded Read Leads to Denial of Service via Helm Chart Tar Bomb

Trivy versions prior to 0.71.0 are vulnerable to CVE-2026-54448, a denial-of-service attack where a crafted Helm chart archive (.tgz) can cause unbounded memory consumption, leading to the OS OOM killer terminating the Trivy process and other services on the host or CI runner.

Trivy supply-chain vulnerability denial-of-service ci-cd
1t 1c
high advisory

Woodpecker CI gRPC Vulnerability Allows Cross-Tenant Agent Impersonation (CVE-2026-50141)

A high-severity vulnerability (CVE-2026-50141) in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` into gRPC metadata, leading to potential privilege escalation and unauthorized access within CI/CD pipelines.

Woodpecker CI v3 privilege-escalation vulnerability grpc ci-cd
1t 1c
critical advisory

GitHub Actions Workflow Command Injection via Issue Comments

A GitHub Actions workflow uses untrusted user input from `issue_comment.body` directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner.

GitHub Actions +1 github-actions command-injection ci-cd
2r 1t