๐Ÿ” CVE Alert

CVE-2026-105767

LOW 3.3

Chainguard Academy (edu) integrate-platform-docs composite action interpolates inputs into shell commands

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

CWE CWE-78
Vendor chainguard
Product chainguard academy (edu)
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for chainguard chainguard academy (edu)

Be the first to know when new low vulnerabilities affecting chainguard chainguard academy (edu) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Chainguard / Chainguard Academy (edu)
7375a80caabcc31c33ec90f29687ed78c13d16ff < fb0efb2537d326ab18c07d620875b8ed2a4b39f3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chainguard-dev/edu/commit/fb0efb2537d326ab18c07d620875b8ed2a4b39f3 github.com: https://github.com/chainguard-dev/edu/pull/3471

Credits

Steve Beattie (https://github.com/stevebeattie) SunnyR (https://github.com/SunnyR) Chainguard (https://chainguard.dev)