HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2025-15617 — Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workfl...

Friday, March 27, 2026 at 06:16 PM UTC·Source: NIST NVD

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.

Analysis

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags. CVSS Score: 6.5. Published: 2026-03-27T18:16:03.173.

Indicators of Compromise (1)

CVE (1)
CVE-2025-15617
Source Attribution

Originally published by NIST NVD on Mar 27, 2026. Verified by: NIST.

Related Threats