CVE Explorer
CVE-2026-44358
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container in place of the acti
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-829","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-427","description":"CWE-427: Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"shared-github-dangerjs","vendor":"espressif","versions":[{"status":"affected","version":"< 1.0.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-829","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-427","description":"CWE-427: Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/espressif/shared-github-dangerjs/commit/d742408028135ea200982b5b2e3e438dc4e5a25d","tags":["x_refsource_MISC"],"url":"https://github.com/espressif/shared-github-dangerjs/commit/d742408028135ea200982b5b2e3e438dc4e5a25d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/references/1
{"name":"https://github.com/espressif/shared-github-dangerjs/security/advisories/GHSA-wm3p-pv54-6w73","tags":["x_refsource_CONFIRM"],"url":"https://github.com/espressif/shared-github-dangerjs/security/advisories/GHSA-wm3p-pv54-6w73"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2af78e522e0f815159b027de0aed452bb253503b8e6ee9e2a42e09b9352f274d · sha256:21edcb71a5b4db7d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.