
NVD assigned CVE-2026-67308 (CVSS 10.0) to a shell injection flaw in Wazuh's GitHub Actions workflows. A crafted VERSION.json in a pull request lets attackers run arbitrary commands and exfiltrate GITHUB_TOKEN plus AWS credentials from self-hosted runners. https://thecircuitry.to/article/nvd-adds-shell-injection-flaw-in-wazuh-github-actions-workflows-as-cve-2026-6730-msaev55r
Post summary
The NVD announced CVE-2026-67308, a critical shell injection flaw in Wazuh GitHub Actions workflows that allows attackers to execute arbitrary commands via a crafted VERSION.json in a pull request, potentially exfiltrating GITHUB_TOKEN and AWS credentials from self-hosted runners.
