PatchSiren cyber security CVE debrief
CVE-2025-15617 Wazuh CVE debrief
CVE-2025-15617 is a high-severity vulnerability in Wazuh version 4.12.0 that exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN and perform unauthorized actions within a limited time window. This vulnerability affects Wazuh deployments using GitHub Actions, and defenders should assess exposure and implement mitigations to prevent unauthorized actions such as pushing malicious commits or altering release tags. The CVE record and NVD entry provide details on the vulnerability, but evidence is limited regarding affected deployments, exploitation, and remediation.
- Vendor
- Wazuh
- Product
- Wazuh (GitHub Actions)
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-27
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-03-27
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Wazuh deployments, GitHub Actions workflows, and software supply chain security should assess exposure and implement mitigations. This includes verifying Wazuh version 4.12.0 deployments, limiting access to GITHUB_TOKEN, and monitoring for suspicious activity related to Wazuh workflow run artifacts. Security teams should prioritize vulnerability management and ensure secure configurations for Wazuh deployments.
Why it matters
CVE-2025-15617 is a high-severity vulnerability in Wazuh version 4.12.0 that exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN and perform unauthorized actions within a limited time window. Defenders should prioritize verifying Wazuh deployments, assessing exposure, and implementing compensating controls.
- Verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts
- Limit access to GITHUB_TOKEN to prevent unauthorized actions
- Monitor for suspicious activity related to Wazuh workflow run artifacts
- Implement compensating controls to mitigate unauthorized actions
Technical summary
The vulnerability in Wazuh version 4.12.0 exposes GitHub Actions workflow artifacts, allowing attackers to extract the GITHUB_TOKEN. This token can be used within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags. The vulnerability affects Wazuh deployments that use GitHub Actions, and defenders should prioritize verifying Wazuh version 4.12.0 deployments, assessing exposure of GitHub Actions workflow artifacts, and implementing compensating controls to mitigate unauthorized actions.
Defensive priority
Defenders should prioritize verifying Wazuh version 4.12.0 deployments, assessing exposure of GitHub Actions workflow artifacts, and implementing compensating controls to mitigate unauthorized actions.
Recommended defensive actions
- Verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts
- Assess and limit access to GITHUB_TOKEN
- Implement compensating controls to mitigate unauthorized actions
- Monitor for suspicious activity related to Wazuh workflow run artifacts
- Review Wazuh workflow configurations for potential security risks
- Conduct a thorough review of Wazuh deployment configurations to ensure secure use of GitHub Actions
- Track exceptions and retest remediated assets to ensure vulnerability resolution
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but evidence is limited regarding affected deployments, exploitation, and remediation. Defenders should verify Wazuh version 4.12.0 deployments for exposure of GitHub Actions workflow artifacts, limit access to GITHUB_TOKEN, and monitor for suspicious activity related to Wazuh workflow run artifacts. Evidence limits and source grounding indicate a need for further verification and assessment of potential impacts on Wazuh deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15617 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15617
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15617 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15617
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wazuh/wazuh/security/advisories/GHSA-6xqr-4q5g-xc7x
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/exposure-of-the-github-token-in-wazuh-workflow-run-artifact
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.