VYPR

Toolkit

by Toolkit Project

CVEs (1)

  • CVE-2020-15228LowOct 1, 2020
    risk 0.23cvss 3.5epss 0.01

    In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format. Workflows that log untrusted data to stdout may invoke these commands, resulting in the…