Vulnerabilities (CVE)

Filtered by vendor Check-spelling
Filtered by product Check-spelling
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32724 1 Check-spelling 1 Check-spelling 2024-11-21 6.8 MEDIUM 9.9 CRITICAL
check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers on `pull_request_target` (or `schedule`), an attacker can send a crafted Pull Request that causes a `GITHUB_TOKEN` to be exposed. With the `GITHUB_TOKEN`, it's possible to push commits to the repository bypassing standard approval processes. Commits to the repository could then s ...

Show More