Stepsecurity operates a focused vulnerability footprint centered on Harden Runner, a GitHub Actions hardening and monitoring tool designed to protect CI/CD pipelines from supply-chain compromise. The observed weakness classes—incorrect authorization, protection mechanism failures, and insufficient logging—reflect the security-critical role of access control and auditability in pipeline enforcement and threat detection.
The number and severity of CVEs published that impact products developed by Stepsecurity over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25598MEDIUM Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub | Feb 9, 2026 | 5.3 | 21 | NO | NO |
CVE-2026-32947MEDIUM Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to by | Mar 20, 2026 | 4.9 | 19 | NO | NO |
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the egress-policy: | Mar 20, 2026 | 2.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stepsecurity.
Media articles that mention a CVE ID that affects a product developed by Stepsecurity — matched by CVE ID, not by vendor name.