Vulnerability Intelligence Report
tj-actions/branch-names Contains Command Injection Vulnerability
CVE-2025-54416
tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks. This is fixed in version 9.0.0
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.2
Impact Score:5.3
EPSS Probability:0.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-77 ↗CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| tj-actions | branch-names | < 9.0.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.525%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2025-07-21T23:18:10 |
| Published | 2025-07-26T03:34:31 |
| Last Updated | 2025-07-28T18:55:45 |
Community Chatter & Buzz