CVE-2026-67308

Source
https://cve.org/CVERecord?id=CVE-2026-67308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67308
Aliases
  • GHSA-95w2-gpvr-q4jh
Published
2026-08-01T12:22:17Z
Modified
2026-10-08T02:51:44Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N CVSS Calculator
Summary
Wazuh GitHub Actions Shell Injection via Fork Pull Request
Details

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67308.json"
}
References

Affected packages

Git / github.com/wazuh/wazuh

Affected ranges

Type
GIT
Repo
https://github.com/wazuh/wazuh
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

coverity-w12-4.*
coverity-w12-4.14.5
coverity-w13-4.*
coverity-w13-4.14.5
coverity-w15-4.*
coverity-w15-4.14.5
coverity-w17-4.*
coverity-w17-4.14.6
coverity-w19-4.*
coverity-w19-4.14.6
coverity-w20-4.*
coverity-w20-4.14.6
v2.*
v2.0
v3.*
v3.1.0
v3.12.0
v3.13.0
v3.13.1
v3.2.0
v3.5.0
v3.6.0
v3.6.1
v3.7.0
v3.8.0
v4.*
v4.14.1
v4.14.3-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67308.json"