Skip to content

Code injection vulnerability in versions 1.13.2 thru 1.13.5

Moderate
rjdbcm published GHSA-2487-9f55-2vg9 May 10, 2025

Package

actions OZI-Project/ozi-publish (GitHub Actions)

Affected versions

>=1.13.2

Patched versions

1.13.6

Description

Impact

Potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code.

Patches

This is patched in 1.13.6

Workarounds

Downgrade to <1.13.2

References

Severity

Moderate

CVE ID

CVE-2025-47271