Exposure Vulnerability in Wazuh by Wazuh Inc.
CVE-2025-15617

6.3MEDIUM

Key Information:

Vendor

Wazuh

Vendor
CVE Published:
27 March 2026

What is CVE-2025-15617?

Wazuh version 4.12.0 contains a significant exposure vulnerability within its GitHub Actions workflow. This flaw allows malicious actors to access sensitive GITHUB_TOKEN stored in uploaded artifacts. Once the token is retrieved, attackers could misuse it within a restricted timeframe to carry out unauthorized actions, such as pushing harmful commits or modifying release tags, thus compromising the integrity of the repository and associated projects.

Affected Version(s)

Wazuh (GitHub Actions) 4.12.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jackhac
nopcorn
nopcorn
vikman90
.