GHSA-r79c-pqj3-577x · Severity: high · Ecosystem: actions — Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull request that introduces a file whose name contains shell command substitution syntax, such as $(...). In affected Super-linter versions, runtime scripts may execute the embedded command during file discovery processing, enabling arbitrary command execution in the workflow runner context. This can be used to disclose the job’s GITHUB_TOKEN depending on how the workflow configures permissions. This vulnerability is fixed in 8.3.1.
Conclusion & alert: CVE-2026-25761 is rated Moderate Risk (60/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.32%). Core evidence: EPSS rose +1.27% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 1.32% | +1.27% |
| 2 | 2026-06-11 | 0.04% | 0.05% | +0.01% |
| 3 | 2026-02-10 | — | 0.04% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-r79c-pqj3-577x · Severity: high · Ecosystem: actions — Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| super-linter_project | super-linter | >= 6.0.0, < 8.3.1 | cpe:2.3:a:super-linter_project:super-linter:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/super-linter/super-linter/releases/tag/v8.3.1 | Product Release Notes |
| https://github.com/super-linter/super-linter/security/advisories/GHSA-r79c-pqj3-577x | Vendor Advisory |