CVE-2025-31479
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2025-31479 affects the canonical/get-workflow-version-action GitHub composite action, which was used to get the commit SHA for GitHub Actions reusable workflows. Before version 1.0.1, if the get-workflow-version-action step failed, the exception output might include the GITHUB_TOKEN, which could be partially displayed in the GitHub Actions logs. Given that anyone with read access to the GitHub repository can view these logs, this vulnerability posed a risk, especially for public repositories. The exposure was brief, as the GITHUB_TOKEN is revoked upon job completion. Users employing the github-token input were vulnerable to this issue, which has been resolved in version 1.0.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.