CVE-2026-105767

Source
https://cve.org/CVERecord?id=CVE-2026-105767
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105767.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105767
Published
2026-10-05T19:48:47Z
Modified
2026-10-08T02:49:19Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Chainguard Academy (edu) integrate-platform-docs composite action interpolates inputs into shell commands
Details

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

Database specific
{
    "cna_assigner": "chainguard",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105767.json"
}
References

Affected packages

Git / github.com/chainguard-dev/edu

Affected ranges

Type
GIT
Repo
https://github.com/chainguard-dev/edu
Events
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
ai-docs
ai-docs-20260423-182027
ai-docs-20260423-185744
ai-docs-20260424-122346
ai-docs-20260426-021819
ai-docs-20260426-030135
ai-docs-20260427-122413
ai-docs-20260427-125209
ai-docs-20260427-135041
ai-docs-20260428-120411
ai-docs-20260428-132624
ai-docs-20260429-133408
ai-docs-20260429-134421
ai-docs-20260429-150259
ai-docs-20260430-121310
ai-docs-bundle
ai-docs-latest

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105767.json"