Impact
A flaw in the operator-foundry component allows mutable GitHub Actions tags, such as @v0 or @v4, to be referenced instead of fixed commit SHAs. This design flaw lets an attacker modify the referenced code through an upstream compromise or by repointing the tag, potentially executing unauthorized code or tampering with the continuous integration pipeline. The weakness maps to CWE-829, indicating insufficient access control or privilege mismanagement.
Affected Systems
The vulnerability affects the operator-foundry component used in GitHub Actions and reusable workflows. No specific product version information is provided; all releases that rely on mutable tags are potentially impacted.
Risk and Exploitability
The CVSS score of 4.2 suggests a moderate but not critical severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation. The attack would require the adversary to alter the tag reference, either by compromising the upstream repository or gaining permission to repoint the tag, a scenario that, while possible, requires prior foothold or access. Thus the threat level is moderate, but the potential impact remains significant if the compromised code is executed.
OpenCVE Enrichment