Github.Com Nektos Act vulnerabilities
3 known vulnerabilities affecting github.com/nektos_act.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-34041P2MEDIUMCVSS 5.0≥ 0, < 0.2.862026-03-27
CVE-2026-34041 [MEDIUM] CWE-74 act: Unrestricted set-env and add-path command processing enables environment injection
act: Unrestricted set-env and add-path command processing enables environment injection
## Summary
act unconditionally processes the deprecated `::set-env::` and `::add-path::` workflow commands, which GitHub Actions disabled in October 2020 (CVE-2020-15228, GHSA-mfwh-5m23-j46w) due to environment injection risks. When a workflow step echoes untrusted data to stdout, an attack
ghsaosv
CVE-2023-22726P3HIGH≥ 0, < 0.2.402023-01-20
CVE-2023-22726 [HIGH] CWE-22 act vulnerable to arbitrary file upload in artifact server
act vulnerable to arbitrary file upload in artifact server
### Impact
The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation.
#### Issue 1: Arbitrary file upload in artifact server (GHSL-2023-004)
The [/upload endpoint](htt
ghsaosv
CVE-2026-34042P3HIGH≥ 0, < 0.2.862026-03-27
CVE-2026-34042 [HIGH] CWE-862 act: actions/cache server allows malicious cache injection
act: actions/cache server allows malicious cache injection
act's built-in actions/cache server listens to connections on all interfaces and allows anyone who can connect to it — including someone anywhere on the internet — to create caches with arbitrary keys and retrieve all existing caches. If one can predict which cache keys will be used by local actions, one can create malicious caches containing whatev
ghsaosv