CVE-2023-49291 is a critical vulnerability affecting tj-actions/branch-names, a GitHub Action used to retrieve branch or tag names. The flaw stems from improper referencing of GitHub context variables, allowing arbitrary code execution via specially crafted branch names. With a CVSS score of 9.8 (CRITICAL), this vulnerability enables attackers to steal secrets or abuse GITHUB_TOKEN permissions. While there is no known active exploitation, exploit code, or significant community discussion, users are strongly advised to upgrade to version 7.0.7 immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0.0CPE matchmatch criteria | cpe:2.3:a:tj-actions:branch-names:*:*:*:*:*:*:*:* | ||
>= 7.0.1, < 7.0.7CPE matchmatch criteria | cpe:2.3:a:tj-actions:branch-names:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.