Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials
Vulnerability Description
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15617
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- jackhac
- nopcorn
- nopcorn
- vikman90
References
More from Wazuh
View All →Affected Vendor
Wazuh
View all reports →