Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-105767 Details

Description

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: 82cea9a6-e9e3-46fe-bdb0-3673de380178CVSS-B:3.3 LOWVector:CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/chainguard-dev/edu/commit/fb0efb2537d326ab18c07d620875b8ed2a4b39f3 82cea9a6-e9e3-46fe-bdb0-3673de380178
https://github.com/chainguard-dev/edu/pull/3471 82cea9a6-e9e3-46fe-bdb0-3673de380178

Weakness Enumeration

CWE-IDCWE NameSource
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')82cea9a6-e9e3-46fe-bdb0-3673de380178

Affected Products

No affected product data is available for this CVE.

Change History

1 change record found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-105767
NVD Published Date:
Oct 5, 2026
NVD Last Modified:
Oct 5, 2026
Source:
82cea9a6-e9e3-46fe-bdb0-3673de380178