{"pocs":[{"id":"1356792379","cve_id":"CVE-2025-54415","name":"gha-lab-f894926966","owner":"pvharmo2","full_name":"pvharmo2\/gha-lab-f894926966","html_url":"https:\/\/github.com\/pvharmo2\/gha-lab-f894926966","description":"Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer\/dag-factory snapshot at 464c75a \u2014 pull_request_target head-SHA checkout executes attacker-controlled hatch scripts in base-repo context","stargazers_count":"0","vuln_description":"dag-factory is a library for Apache Airflow\u00ae to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity vulnerability has been identified in the cicd.yml workflow within the astronomer\/dag-factory GitHub repository. The workflow, specifically when triggered by pull_request_target, is susceptible to exploitation, allowing an attacker to execute arbitrary code within the GitHub Actions runner environment. This misconfiguration enables an attacker to establish a reverse shell, exfiltrate sensitive secrets, including the highly-privileged GITHUB_TOKEN, and ultimately gain full control over the repository. This is fixed in version 0.23.0a9.","created_at":"2026-09-04 15:41:28","updated_at":"2026-09-04 15:43:17","pushed_at":"2026-09-04 16:02:18","inserted_at":"2026-09-04 22:37:19"},{"id":"1356747756","cve_id":"CVE-2025-53546","name":"gha-lab-6926364d94","owner":"pvharmo2","full_name":"pvharmo2\/gha-lab-6926364d94","html_url":"https:\/\/github.com\/pvharmo2\/gha-lab-6926364d94","description":"Security research lab reproducing CVE-2025-53546 (GHSA-h87r-5w74-qfm4): pull_request_target arbitrary code execution in RSSNext\/Folo's auto-fix lint workflow \u2014 authorized, isolated reproduction","stargazers_count":"0","vuln_description":"Folo organizes feeds content into one timeline. Using pull_request_target on .github\/workflows\/auto-fix-lint-format-commit.yml can be exploited by attackers, since untrusted code can be executed having full access to secrets (from the base repo). By exploiting the vulnerability is possible to exfiltrate GITHUB_TOKEN which has high privileges. GITHUB_TOKEN can be used to completely overtake the repo since the token has content write privileges. This vulnerability is fixed in commit 585c6a591440cd39f92374230ac5d65d7dd23d6a.","created_at":"2026-09-04 14:51:19","updated_at":"2026-09-04 14:54:52","pushed_at":"2026-09-04 15:00:16","inserted_at":"2026-09-04 22:37:19"},{"id":"1356715588","cve_id":"CVE-2025-8518","name":"CVE-2025-8518","owner":"HORKimhab","full_name":"HORKimhab\/CVE-2025-8518","html_url":"https:\/\/github.com\/HORKimhab\/CVE-2025-8518","description":"CVE-2025-8518 - Draft or TODO","stargazers_count":"0","vuln_description":"A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin\/controller\/editor\/code.php of the component Code Editor. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.6 is able to address this issue. The name of the patch is f684f3e374d04db715730fc4796e102f5ebcacb2. It is recommended to upgrade the affected component.","created_at":"2026-09-04 14:04:56","updated_at":"2026-09-04 14:05:17","pushed_at":"2026-09-04 14:05:00","inserted_at":"2026-09-04 22:37:19"}]}