CVE-2025-53104: Command injection via GitHub Actions workflow in gluestack-ui
ID: 9a517b9a-6312-521d-839e-bc2d2ad1d553
STIX ID: report--9a517b9a-6312-521d-839e-bc2d2ad1d553
Feed Name: Sysdig Blog
Threat Score
The Sysdig Threat Research Team disclosed CVE-2025-53104 in gluestack/gluestack-ui, a critical (CVSS 9.1) command-injection vulnerability in a GitHub Actions workflow that unsafely writes GitHub Discussion title/body to GITHUB_OUTPUT. An attacker can craft a discussion to execute arbitrary commands on the runner, exfiltrate GITHUB_TOKEN and other secrets, and potentially publish or modify NPM packages, enabling a severe supply-chain compromise; a patch was released on June 13, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
