


Perceptive Security
SOC/SIEM Consultancy

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull …
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 16:10:40
Source:
nvd.nist.gov
Supply Chain & Dependencies, Identity & Access, Data Breach & Exfiltration, Security Tools
CVE-2026-67308 describes a shell injection vulnerability in Wazuh's GitHub Actions workflows affecting versions before commit 44bf114. Attackers can exploit this by submitting pull requests containing crafted VERSION.json files with shell metacharacters injected into environment variables. These variables are directly interpolated into workflow run steps without proper sanitization, enabling arbitrary command execution. The attack vector is particularly dangerous on self-hosted runners where sensitive secrets such as GITHUB_TOKEN and AWS credentials can be exfiltrated. The vulnerability is triggered via fork pull requests, a common supply chain attack vector. Successful exploitation could lead to full compromise of CI/CD pipelines and exposure of cloud credentials. This represents a significant risk to organizations using Wazuh's open-source security platform with self-hosted GitHub Actions runners.
Technical details
Mitigation steps:
Affected products:
Wazuh GitHub Actions workflows (before commit 44bf114)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67308
https://github.com/wazuh/wazuh/security/advisories/GHSA-95w2-gpvr-q4jh
https://www.vulncheck.com/advisories/wazuh-github-actions-shell-injection-via-fork-pull-request
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
