Skip to main content

CVE-2026-105767: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Chainguard Chainguard Academy (edu)

0
Low
VulnerabilityCVE-2026-105767cvecve-2026-105767cwe-78
Published: 10/05/2026 (10/05/2026, 19:48:47 UTC)
Source: CVE Database V5
Vendor/Project: Chainguard
Product: Chainguard Academy (edu)

Description

CVE-2026-105767 is an OS command injection vulnerability in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu). The flaw arises from improper neutralization of special elements in inputs used directly in Bash gcloud storage cp commands. This allows an actor controlling the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner. However, the only known caller passes repository secrets and runs on trusted triggers, so untrusted inputs were not known to reach the vulnerable code. The CVSS score is low (2.1).

CVSS v4.0

Score 2.1low

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
High
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

Chainguard

Chainguard Academy (edu)

GitHub Actionsmore threats →cve
Chainguard Academy (edu)
pkg:github/Chainguard Academy (edu)

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 20:33:29 UTC

Technical Analysis

This vulnerability (CVE-2026-105767) involves improper neutralization of special elements in OS commands (CWE-78) within the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu). Specifically, inputs project_id and storage_bucket are interpolated directly into Bash gcloud storage cp commands via ${{ inputs.* }} expressions without sufficient sanitization, enabling arbitrary shell command execution on the GitHub Actions runner if an attacker controls these inputs. The vulnerability existed from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff until fixed in commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3. The only in-repository caller used repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.

Potential Impact

An attacker who can control the project_id or storage_bucket inputs in the vulnerable GitHub Action could execute arbitrary shell commands on the GitHub Actions runner. However, since the only known caller uses repository secrets and trusted triggers, the practical risk is limited. The CVSS 4.0 score is 2.1 (low severity), reflecting the limited attack vector and required privileges.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability was fixed in commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3. Users should update to the fixed version of the integrate-platform-docs composite GitHub Action. Until then, restrict inputs to trusted sources and avoid exposing project_id or storage_bucket inputs to untrusted users.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
chainguard
Date Reserved
2026-10-05T19:21:04.930Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac4063a2cdf04f65634e092

Added to database: 10/05/2026, 20:19:06 UTC

Last enriched: 10/05/2026, 20:33:29 UTC

Last updated: 10/05/2026, 20:34:04 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses