CVE 9.1 CRITICAL

tj-actions/branch-names Contains Command Injection Vulnerability_CVE-2025-54416

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Description

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks. This is fixed in version 9.0.0

Basic Information

ID CVE-2025-54416
Source GitHub_M
Published Jul 26, 2025 at 03:34
Modified Jul 28, 2025 at 18:55

Affected Product

Vendor tj-actions
Product branch-names
Version < 9.0.0
Affected Versions tj-actions branch-names < 9.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.