CVE-2026-105767
Received Received - Intake

Improper OS Command Injection in Chainguard Academy integrate-platform-docs GitHub Action

Vulnerability report for CVE-2026-105767, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: 82cea9a6-e9e3-46fe-bdb0-3673de380178

Description

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Chainguard Chainguard Academy (edu) 7375a80caabcc31c33ec90f29687ed78c13d16ff

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper neutralization of special elements in the integrate-platform-docs composite GitHub Action of Chainguard Academy. An attacker who controls the project_id or storage_bucket inputs could execute arbitrary shell commands on the GitHub Actions runner. The inputs are directly interpolated into Bash gcloud storage cp commands via template expressions like ${{ inputs.* }}, enabling command injection.

Detection Guidance

To detect this vulnerability, inspect GitHub Actions workflow files for improper use of inputs in shell commands. Look for ${{ inputs.* }} expressions directly interpolated into Bash commands like gcloud storage cp. Use tools like zizmor, actionlint, and shellcheck to scan workflows for injection risks and shell script issues.

Impact Analysis

If exploited, this vulnerability allows attackers to run arbitrary commands on the GitHub Actions runner. This could lead to unauthorized access, data theft, or modification of repository contents. However, the only known caller used trusted triggers and repository secrets, so untrusted input was not exposed.

Compliance Impact

This vulnerability allows arbitrary shell command execution via manipulated inputs in GitHub Actions workflows. For GDPR, it could lead to unauthorized data access or processing if exploited, violating principles of lawfulness and security. For HIPAA, it risks exposing protected health information if workflows handle such data without proper controls.

Mitigation Strategies

Review GitHub Actions workflows for unsafe input interpolation in commands. Move template expressions like ${{ inputs.* }} out of run/script bodies into environment variables. Scope GITHUB_TOKEN permissions per job instead of using blanket workflow-level permissions. Set explicit persist-credentials for checkout steps and apply shellcheck-quoting fixes to prevent injection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105767. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart