<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T05:01:39.919471+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278768</id>
    <title>EUVD-2026-278768</title>
    <updated>2026-10-09T05:01:39.967519+00:00</updated>
    <content>EUVD-2026-278768</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34041</id>
    <title>fkie_cve-2026-34041</title>
    <updated>2026-10-09T05:01:39.967559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands, which was disabled due to environment injection risks. When a workflow step echoes untrusted data to stdout, an attacker can inject these commands to set arbitrary environment variables or modify the PATH for all subsequent steps in the job. This issue has been patched in version 0.2.86.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xmgr-9pqc-h5vw</id>
    <title>GHSA-xmgr-9pqc-h5vw — act: Unrestricted set-env and add-path command processing enables environment injection</title>
    <updated>2026-10-09T05:01:39.967594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nektos/act</p>
<p>## Summary</p>
<p>act unconditionally processes the deprecated `::set-env::` and `::add-path::` workflow commands, which GitHub Actions disabled in October 2020 (CVE-2020-15228, GHSA-mfwh-5m23-j46w) due to environment injection risks. When a workflow step echoes untrusted data to stdout, an attacker can inject these commands to set arbitrary environment variables or modify the PATH for all subsequent steps in the job. This makes `act` strictly less secure than GitHub Actions for the same workflow file.</p>
<p>## Vulnerable Code</p>
<p>**`pkg/runner/command.go`, lines 52-58:**</p>
<p>```go
switch command {
case "set-env":
    rc.setEnv(ctx, kvPairs, arg)
case "set-output":
    rc.setOutput(ctx, kvPairs, arg)
case "add-path":
    rc.addPath(ctx, arg)
```</p>
<p>There is no check for the `ACTIONS_ALLOW_UNSECURE_COMMANDS` environment variable. The string `ACTIONS_ALLOW_UNSECURE_COMMANDS` does not appear anywhere in the act codebase.</p>
<p>On GitHub Actions, these commands are rejected unless `ACTIONS_ALLOW_UNSECURE_COMMANDS=true` is set:</p>
<p>```
Error: The `set-env` command is disabled. Please upgrade to using Environment Files
  or opt-in by setting ACTIONS_ALLOW_UNSECURE_COMMANDS=true.
```</p>
<p>## PoC: Environment and PATH Injection via PR Title</p>
<p>**Tested on:** act 0.2.84, Docker Desktop 29.1.2, macOS Darwin 24.5.0</p>
<p>**Step 1 — Create a workflow that logs PR metadata:**</p>
<p>`.github/workflows/vuln.yml`:
```yaml
name: Vulnerable Workflow
on: [pull_request]</p>
<p>jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xmgr-9pqc-h5vw"/>
  </entry>
</feed>
