No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 30 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif shared-github-dangerjs |
|
| Vendors & Products |
Espressif
Espressif shared-github-dangerjs |
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container in place of the action's own code. This vulnerability is fixed in 1.0.1. | |
| Title | Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint | |
| Weaknesses | CWE-427 CWE-829 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-30T01:56:50.710Z
Reserved: 2026-05-05T20:15:20.630Z
Link: CVE-2026-44358
Updated: 2026-05-30T01:56:46.246Z
Status : Received
Published: 2026-05-28T16:16:24.210
Modified: 2026-05-28T16:16:24.210
Link: CVE-2026-44358
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:48:26Z