CVE-2025-49013
Last modified
CVE-2025-49013 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions workflows. This introduces a code injection vulnerability: a malicious actor submitting a crafted pull request review containing shell metacharacters or commands could execute arbitrary shell code on the GitHub Actions runner. This can lead to arbitrary command execution with the permissions of the workflow, potentially compromising CI infrastructure, secrets, and build outputs. Developers who maintain or contribute to the repos WilderForge/WilderForge, WilderForge/ExampleMod, WilderForge/WilderWorkspace, WilderForge/WildermythGameProvider, WilderForge/AutoSplitter, WilderForge/SpASM, WilderForge/thrixlvault, WilderForge/MassHash, and/or WilderForge/DLC_Disabler; as well as users who fork any of the above repositories and reuse affected GitHub Actions workflows, are affected. End users of any the above software and users who only install pre-built releases or artifacts are not affected. This vulnerability does not impact runtime behavior of the software or compiled outputs unless those outputs were produced during exploitation of this vulnerability. A current workaround is to disable GitHub Actions in affected repositories, or remove the affected workflows.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-49013?
How severe is CVE-2025-49013?
How do I fix CVE-2025-49013?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-49008Atheos is a self-hosted browser-based cloud integrated devel…9.4
- CVE-2025-49009Para is a multitenant backend server/framework for object pe…6.2
- CVE-2025-4901A vulnerability classified as problematic was found in D-Lin…6.5
- CVE-2025-49010OpenSC is an open source smart card tools and middleware. Pr…6.8
- CVE-2025-49011SpiceDB is an open source database for storing and querying …5.3
- CVE-2025-49012Himmelblau is an interoperability suite for Microsoft Azure …5.4
- CVE-2025-49014jq is a command-line JSON processor. In version 1.8.0 a heap…5.5
- CVE-2025-49015The Couchbase .NET SDK (client library) before 3.7.1 does no…4.9
- CVE-2025-4902A vulnerability, which was classified as problematic, has be…7.5
- CVE-2025-49028Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail…7.1
- CVE-2025-49029Improper Control of Generation of Code ('Code Injection') vu…9.1
- CVE-2025-4903A vulnerability, which was classified as critical, was found…7.5
Are you affected by CVE-2025-49013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
