Skip to content

Conversation

@kawsarahmedbhuiyan
Copy link
Contributor

Adds recently published GitHub Actions vulnerability GHSA-pwf7-47c3-mfhx to the OSV advisories database.

Vulnerability Details

  • Package: j178/prek-action
  • Advisory ID: GHSA-pwf7-47c3-mfhx
  • Severity: Critical
  • CWE: CWE-94
  • Published: September 29, 2025
  • Vulnerable versions: <=1.0.5
  • Fixed in: 1.0.6

References

Add j178/prek-action arbitrary code injection vulnerability to the
vulnerability database.

- Package: j178/prek-action
- Severity: 9.9 Critical (CWE-94)
- Vulnerable versions: <=1.0.5
- Fixed in: 1.0.6
- Published: 2025-09-29

Reference: GHSA-pwf7-47c3-mfhx
@kawsarahmedbhuiyan kawsarahmedbhuiyan requested a review from a team as a code owner November 27, 2025 21:30
@fproulx-boostsecurity fproulx-boostsecurity merged commit f2b7ebe into boostsecurityio:main Nov 28, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants