Description
A flaw was found in operator-foundry. GitHub Actions and reusable workflows within the component are referenced using mutable tags (e.g., `@v0`, `@v4`) instead of fixed commit SHAs. This allows an attacker to potentially alter the code executed in the Continuous Integration (CI) pipeline through an upstream compromise or by re-pointing a tag, leading to unauthorized code execution or manipulation.
Published: n/a
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Code Execution
Action: Update Component
AI Analysis

Impact

A flaw in the operator-foundry component allows mutable GitHub Actions tags, such as @v0 or @v4, to be referenced instead of fixed commit SHAs. This design flaw lets an attacker modify the referenced code through an upstream compromise or by repointing the tag, potentially executing unauthorized code or tampering with the continuous integration pipeline. The weakness maps to CWE-829, indicating insufficient access control or privilege mismanagement.

Affected Systems

The vulnerability affects the operator-foundry component used in GitHub Actions and reusable workflows. No specific product version information is provided; all releases that rely on mutable tags are potentially impacted.

Risk and Exploitability

The CVSS score of 4.2 suggests a moderate but not critical severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation. The attack would require the adversary to alter the tag reference, either by compromising the upstream repository or gaining permission to repoint the tag, a scenario that, while possible, requires prior foothold or access. Thus the threat level is moderate, but the potential impact remains significant if the compromised code is executed.

Generated by OpenCVE AI on September 9, 2026 at 06:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update operator-foundry to a release that pins commit SHAs for GitHub Actions references
  • Modify all workflow files to replace mutable tags like @v0 with the exact commit SHA of the intended version
  • Restrict workflow execution to trusted sources or disable the workflow temporarily while a fix is applied

Generated by OpenCVE AI on September 9, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-foundry. GitHub Actions and reusable workflows within the component are referenced using mutable tags (e.g., `@v0`, `@v4`) instead of fixed commit SHAs. This allows an attacker to potentially alter the code executed in the Continuous Integration (CI) pipeline through an upstream compromise or by re-pointing a tag, leading to unauthorized code execution or manipulation.
Title operator-foundry: operator-foundry: GitHub Actions and reusable workflow not pinned to commit SHA
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87050 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere