Security: github/gh-aw
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Safe-output artifacts may expose CI trigger tokensGHSA-8h78-hpm7-29gg published
Aug 27, 2026 by pelikhanCritical -
gh-aw: the confused-deputy check does not cover pull_request_target, so a labeled fork PR activates the agent on the labeler's permissionsGHSA-r8gh-v7wv-8g7h published
Aug 16, 2026 by pelikhanHigh -
gh-aw: cache-memory restores an attacker-controlled .git/config and executes a git filter driver on the runner hostGHSA-gh77-fhfh-2mc5 published
Aug 16, 2026 by pelikhanHigh -
gh-aw: safe-output validator forwards undeclared agent fields to the appliers (scope escape / mass assignment)GHSA-jxrq-hq57-gwwm published
Aug 8, 2026 by pelikhanCritical -
gh-aw: URL allowlist bypass via userinfo @ in the content sanitizer (exfiltration channel)GHSA-73j6-rcxw-76w7 published
Aug 7, 2026 by pelikhanModerate -
gh-aw: github.event.* command injection via heredoc-blind template guardrails (MCP config, all engines)GHSA-796c-cr8h-rr49 published
Aug 25, 2026 by pelikhanHigh -
gh-aw: unauthenticated prompt-injection to code execution in the shipped ai-moderator workflowGHSA-2cwf-x2h8-mqj5 published
Aug 7, 2026 by pelikhanModerate -
Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts`GHSA-846c-fpfg-rj9m published
Aug 29, 2026 by lpcoxCritical -
command injection in compiled workflow via unsanitized `sandbox.mcp.env` exportsGHSA-j77w-g4jj-hp99 published
Aug 7, 2026 by pelikhanCritical -
Safe-outputs config emitter: JSON injection via templated values despite env-var indirectionGHSA-2wjq-689w-pprh published
Aug 6, 2026 by pelikhanHigh