Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-49291

28
FAUCET Score

CVE-2023-49291 is a critical vulnerability affecting tj-actions/branch-names, a GitHub Action used to retrieve branch or tag names. The flaw stems from improper referencing of GitHub context variables, allowing arbitrary code execution via specially crafted branch names. With a CVSS score of 9.8 (CRITICAL), this vulnerability enables attackers to steal secrets or abuse GITHUB_TOKEN permissions. While there is no known active exploitation, exploit code, or significant community discussion, users are strongly advised to upgrade to version 7.0.7 immediately as no workarounds exist.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.0.0CPE matchmatch criteria
cpe:2.3:a:tj-actions:branch-names:*:*:*:*:*:*:*:*
>= 7.0.1, < 7.0.7CPE matchmatch criteria
cpe:2.3:a:tj-actions:branch-names:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.3CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.45%
Probability of exploitation in next 30 days
EPSS Percentile
70.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0145 is in the 57th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

actionspatch availablevia ghsa
Product: tj-actions/branch-namesFixed in: 7.0.7
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

actionsGHSA-8v8w-v8xg-79rfcritical

tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection

Dec 5, 2023

References

github.com / tj-actions/branch-names/commit/4923d1ca41f928c24f1c1b3af9daaadfb71e6337
Patch
github.com / tj-actions/branch-names/commit/6c999acf206f5561e19f46301bb310e9e70d8815
Patch
github.com / tj-actions/branch-names/commit/726fe9ba5e9da4fcc716223b7994ffd0358af060
Patch
github.com / tj-actions/branch-names/security/advisories/GHSA-8v8w-v8xg-79rf
ExploitVendor Advisory
securitylab.github.com / research/github-actions-untrusted-input
ExploitThird Party Advisory