CVE-2026-12567 - Symlink-following arbitrary write via github_workflows module
CVE ID :CVE-2026-12567
Published : June 17, 2026, 9:51 p.m. | 1 hour, 47 minutes ago
Description :The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 9:51 p.m. | 1 hour, 47 minutes ago
Description :The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...