top of page
perceptive_background_267k.jpg

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull …

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Identity & Access, Data Breach & Exfiltration, Security Tools

CVE-2026-67308 describes a shell injection vulnerability in Wazuh's GitHub Actions workflows affecting versions before commit 44bf114. Attackers can exploit this by submitting pull requests containing crafted VERSION.json files with shell metacharacters injected into environment variables. These variables are directly interpolated into workflow run steps without proper sanitization, enabling arbitrary command execution. The attack vector is particularly dangerous on self-hosted runners where sensitive secrets such as GITHUB_TOKEN and AWS credentials can be exfiltrated. The vulnerability is triggered via fork pull requests, a common supply chain attack vector. Successful exploitation could lead to full compromise of CI/CD pipelines and exposure of cloud credentials. This represents a significant risk to organizations using Wazuh's open-source security platform with self-hosted GitHub Actions runners.

Technical details

Mitigation steps:

Affected products:

Wazuh GitHub Actions workflows (before commit 44bf114)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page