← Volver al buscador de CVEs

CVE-2026-44358

Espressif Shared GitHub DangerJS

Descripción

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action-s entrypoint.sh invoked DangerJS from the caller-s workspace after copying the fork-s checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container in place of the action-s own code. This vulnerability is fixed in 1.0.1.

CVSS 8.2EPSS 0.181%Riesgo 0.83
Ver fuente
Publicación
2026-05-28 16:16:24
Versiones afectadas
<1.0.1
Tipo
Otro
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N