← Back to CVE List
Vulnerability Intelligence Report
tj-actions/branch-names Contains Command Injection Vulnerability

CVE-2025-54416

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Action workflow which allows arbitrary command execution in downstream workflows. This issue arises due to inconsistent input sanitization and unescaped output, enabling malicious actors to exploit specially crafted branch names or tags. While internal sanitization mechanisms have been implemented, the action outputs remain vulnerable, exposing consuming workflows to significant security risks. This is fixed in version 9.0.0

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.2
Impact Score:5.3
EPSS Probability:0.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-77 ↗CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
tj-actions branch-names < 9.0.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.525%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-07-21T23:18:10
Published2025-07-26T03:34:31
Last Updated2025-07-28T18:55:45

LINK COPIED TO CLIPBOARD