{"id":"CVE-2026-105767","title":"Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07…","summary":"Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-78"],"vendor":"Chainguard","product":"Chainguard Academy (edu)","affected":["academy_edu >= 7375a80caabcc31c33ec90f29687ed78c13d16ff < fb0efb2537d326ab18c07d620875b8ed2a4b39f3"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:20.840","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105767","references":[{"url":"https://github.com/chainguard-dev/edu/commit/fb0efb2537d326ab18c07d620875b8ed2a4b39f3","label":"82cea9a6-e9e3-46fe-bdb0-3673de380178"},{"url":"https://github.com/chainguard-dev/edu/pull/3471","label":"82cea9a6-e9e3-46fe-bdb0-3673de380178"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T20:32:56.654Z","slug":"CVE-2026-105767","body":"## Overview\n\nImproper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}