VYPR

Actions

by GitHub

CVEs (2)

  • CVE-2026-44590CriMay 27, 2026
    risk 0.54cvss 9.3epss 0.01

    Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the…

  • CVE-2026-31852CriMar 11, 2026
    risk 0.00cvss 10.0epss 0.00

    Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this…