logo

CVE-2025-53104: Command injection via GitHub Actions workflow in gluestack-ui

ID: e7113578-7364-58df-afa4-fc79f64956bb

STIX ID: report--e7113578-7364-58df-afa4-fc79f64956bb

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2025-07-07

Date Updated: 2026-05-01

...
...

The Sysdig Threat Research Team disclosed CVE-2025-53104, a critical (CVSS v3.1 base score 9.1) command-injection flaw in the gluestack-ui repository's GitHub Actions discussion-to-slack workflow that lets attacker-controlled GitHub Discussion titles/bodies execute arbitrary commands on runners, potentially exfiltrating GITHUB_TOKEN and other secrets and enabling repository tampering and malicious NPM package publication; the issue was reported June 11, 2025 and patched by gluestack on June 13, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.