Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2026-76847
- EPSS -
- Veröffentlicht 24.08.2026 13:12:02
- Zuletzt bearbeitet 24.08.2026 14:17:02
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and D...
9.8
CVE-2026-34041
- EPSS 0.62%
- Veröffentlicht 31.03.2026 01:43:25
- Zuletzt bearbeitet 06.04.2026 15:34:15
act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands, which was disabled due to environment injection risks. When a wor...
1