tag
Supply-Chain
Critical
tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416·
tj-actions/branch-names GitHub Action
patched
High
Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417·
aws-cdk-lib (npm package), NodejsFunction L2 construct
patched
Critical
Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590·
sherlock-project/sherlock (GitHub Actions workflow validate_modified_targets.yml)
patched
High
psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm)·
psf/black GitHub Action
patched
High
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a)·
Prefect (workflow orchestration platform), GitRepository storage class
patched
High
Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947·
Orval (OpenAPI-to-TypeScript client generator), version 7.10.0
patched
High
Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786·
tar npm package (Node.js)
unpatched
High
node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97·
node-tar (npm package tar)
patched
High
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671·
Next.js 16.2.4 (bundles picomatch 4.0.3 at node_modules/next/dist/compiled/picomatch/)
patched
High
HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04·
hashicorp/go-getter (used by Terraform, Nomad, Packer, Waypoint)
patched
High
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807·
AI inference/model-loading frameworks that resolve custom model classes via auto_map before validating trust_remote_code (pattern seen in vLLM/Transformers-style loaders)
unpatched