OZI GitHub Action Code Injection Vulnerability

Vulnerability

A code injection vulnerability has been identified in the OZI GitHub Action, specifically in versions 1.13.2 prior to 1.13.5. This vulnerability arises from the PR creation logic, which improperly handles potentially untrusted data. A malicious actor could exploit this by crafting a branch name that injects arbitrary code. The issue has been addressed in version 1.13.6. As a temporary measure, users can downgrade to a version prior to 1.13.2.

Impact

Exploitation of this vulnerability allows for arbitrary code injection, which could be executed in the context of the GitHub Action.

Remediation

Users can upgrade to OZI GitHub Action version 1.13.6, where this vulnerability has been patched. Alternatively, users can downgrade to a version prior to 1.13.2.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.5
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.