HIGH8.8Go
GHSA-pc99-qmg4-rcff· CVE-2023-22726, GO-2023-1504act vulnerable to arbitrary file upload in artifact server
Modified: 9/10/2026
package
pkg:go/github.com/nektos/act
act vulnerable to arbitrary file upload in artifact server
Modified: 9/10/2026
act: actions/cache server allows malicious cache injection
Modified: 4/2/2026
act: Unrestricted set-env and add-path command processing enables environment injection
Modified: 4/2/2026
act vulnerable to arbitrary file upload in artifact server in github.com/nektos/act
Modified: 3/3/2026
act: actions/cache server allows malicious cache injection in github.com/nektos/act
Modified: 4/2/2026
act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act
Modified: 4/2/2026