CVE-2025-32953

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 200

Summary

CVE-2025-32953 is a vulnerability affecting the z80pack emulator's GitHub workflow in versions prior to 1.38. During this period, the workflow's `makefile-ubuntu.yml` file uses the `actions/upload-artifact@v4` action to upload a zip of the current directory as the `z80pack-ubuntu` artifact. This artifact contains the `.git/config` file, which holds the run's GitHub token. Attackers could extract the token from the artifact during the brief period it's available, enabling them to manipulate your GitHub repository using the Github API. The issue has been addressed with commit bd95916.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share