PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15617 Wazuh CVE debrief

CVE-2025-15617 is a high-severity vulnerability in Wazuh version 4.12.0 that exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN and perform unauthorized actions within a limited time window. This vulnerability affects Wazuh deployments using GitHub Actions, and defenders should assess exposure and implement mitigations to prevent unauthorized actions such as pushing malicious commits or altering release tags. The CVE record and NVD entry provide details on the vulnerability, but evidence is limited regarding affected deployments, exploitation, and remediation.

Vendor
Wazuh
Product
Wazuh (GitHub Actions)
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-27
Original CVE updated
2026-09-30
Advisory published
2026-03-27
Advisory updated
2026-09-30

Who should care

Defenders responsible for Wazuh deployments, GitHub Actions workflows, and software supply chain security should assess exposure and implement mitigations. This includes verifying Wazuh version 4.12.0 deployments, limiting access to GITHUB_TOKEN, and monitoring for suspicious activity related to Wazuh workflow run artifacts. Security teams should prioritize vulnerability management and ensure secure configurations for Wazuh deployments.

Why it matters

CVE-2025-15617 is a high-severity vulnerability in Wazuh version 4.12.0 that exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN and perform unauthorized actions within a limited time window. Defenders should prioritize verifying Wazuh deployments, assessing exposure, and implementing compensating controls.

  • Verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts
  • Limit access to GITHUB_TOKEN to prevent unauthorized actions
  • Monitor for suspicious activity related to Wazuh workflow run artifacts
  • Implement compensating controls to mitigate unauthorized actions

Technical summary

The vulnerability in Wazuh version 4.12.0 exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN. This token can be used within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags. The vulnerability affects Wazuh deployments that use GitHub Actions, and defenders should prioritize verifying Wazuh version 4.12.0 deployments, assessing exposure of GitHub Actions workflow artifacts, and implementing compensating controls to mitigate unauthorized actions.

Defensive priority

Defenders should prioritize verifying Wazuh version 4.12.0 deployments, assessing exposure of GitHub Actions workflow artifacts, and implementing compensating controls to mitigate unauthorized actions.

Recommended defensive actions

  • Verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts
  • Assess and limit access to GITHUB_TOKEN
  • Implement compensating controls to mitigate unauthorized actions
  • Monitor for suspicious activity related to Wazuh workflow run artifacts
  • Review Wazuh workflow configurations for potential security risks
  • Conduct a thorough review of Wazuh deployment configurations to ensure secure use of GitHub Actions
  • Track exceptions and retest remediated assets to ensure vulnerability resolution

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but evidence is limited regarding affected deployments, exploitation, and remediation. Defenders should verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts, limit access to GITHUB_TOKEN, and monitor for suspicious activity related to Wazuh workflow run artifacts. Evidence limits and source grounding indicate a need for further verification and assessment of potential impacts on Wazuh deployments.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15617 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15617

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15617 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15617

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-6xqr-4q5g-xc7x

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/exposure-of-the-github-token-in-wazuh-workflow-run-artifact

    [email protected] - Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.