{"id":"CVE-2025-32958","summary":"Adept exposed the GITHUB_TOKEN in workflow run artifact","details":"Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's GITHUB_TOKEN. Seeing as the artifact can be downloaded prior to the end of the workflow, there is a few seconds where an attacker can extract the token from the artifact and use it with the Github API to push malicious code or rewrite release commits in the AdeptLanguage/Adept repository. This issue has been patched in commit a1a41b7.","aliases":["GHSA-8c7v-vccv-cx4q"],"modified":"2026-08-12T03:51:42.830551170Z","published":"2025-04-21T20:45:40.082Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32958.json","unresolved_ranges":[{"extracted_events":[{"fixed":"a1a41b7"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://github.com/AdeptLanguage/Adept/security/advisories/GHSA-8c7v-vccv-cx4q"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32958"},{"type":"FIX","url":"https://github.com/AdeptLanguage/Adept/commit/a1a41b72cdf1bebfc0cf6d7b3a8350e6406b2220"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/adeptlanguage/adept","events":[{"introduced":"0"},{"fixed":"a1a41b72cdf1bebfc0cf6d7b3a8350e6406b2220"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.7","v2.6","v2.6-preview-build-feb-22-2022","v2.6-preview-build-dec-2-2021","v2.5","v2.5-preview-build-oct-18-2021","v2.4","v2.3","v2.2","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32958.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}