CVE-2026-105767

LOWCVSS 3.3/10EPSS 0.18%

Last modified

CVE-2026-105767 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
ChainguardChainguard Academy (edu)>= 7375a80caabcc31c33ec90f29687ed78c13d16ff, < fb0efb2537d326ab18c07d620875b8ed2a4b39f3

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-105767?
Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.
How severe is CVE-2026-105767?
CVE-2026-105767 has a CVSS score of 3.3/10 (LOW severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-105767?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-105767?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST