CVE-2023-27581 is a critical vulnerability affecting versions 4.0.0 through 4.4.0 of the github-slug-action GitHub Action, which insecurely processes the github.head_ref parameter. This allows an attacker to inject malicious code via a crafted pull request branch name, leading to arbitrary code execution on GitHub runners and potential exfiltration of CI pipeline secrets. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.4.1CPE matchmatch criteria | cpe:2.3:a:github-slug-action_project:github-slug-action:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.