CVE-2025-31479

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 532

Summary

CVE-2025-31479 affects the canonical/get-workflow-version-action GitHub composite action, which was used to get the commit SHA for GitHub Actions reusable workflows. Before version 1.0.1, if the get-workflow-version-action step failed, the exception output might include the GITHUB_TOKEN, which could be partially displayed in the GitHub Actions logs. Given that anyone with read access to the GitHub repository can view these logs, this vulnerability posed a risk, especially for public repositories. The exposure was brief, as the GITHUB_TOKEN is revoked upon job completion. Users employing the github-token input were vulnerable to this issue, which has been resolved in version 1.0.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share