CVE-2025-47271 - CVE House
Back to Database
Status published Medium CVE-2025-47271

OZI-Project/ozi-publish Code Injection vulnerability

Vulnerability Description

The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code. This is patched in 1.13.6. As a workaround, one may downgrade to a version prior to 1.13.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-47271

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

OZI-Project

View all reports →

Affected Software

publish
Vulnerable Versions:
>= 1.13.2, < 1.13.6

Timeline

Official Publish: May 12th, 2025
Last Modified: May 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors