THREAT OPS › Threat News › [NVD] CVE-2026-67308 (CRITICAL 10.0) — Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are
[NVD] CVE-2026-67308 (CRITICAL 10.0) — Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are
CVE-2026-67308 CVSS: 10.0 CRITICAL Published: 2026-08-01T13:17:00.553
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling co
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67308cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67308