{"id":"CVE-2025-54430","summary":"dedupe is vulnerable to secret exfiltration via `issue_comment`","details":"dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Before commit 3f61e79, a critical severity vulnerability has been identified within the .github/workflows/benchmark-bot.yml workflow, where a issue_comment can be triggered using the @benchmark body. This workflow is susceptible to exploitation as it checkout the ${{ github.event.issue.number }}, which correspond to the branch of the PR manipulated by potentially malicious actors, and where untrusted code may be executed. Running untrusted code may lead to the exfiltration of GITHUB_TOKEN, which in this workflow has write permissions on most of the scopes - in particular the contents one - and could lead to potential repository takeover. This is fixed by commit 3f61e79.","aliases":["GHSA-wrg3-xqw8-m85p"],"modified":"2026-08-12T03:51:32.797115317Z","published":"2025-07-30T13:41:59.975Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54430.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3f61e79102910bd355e920a2df7e44c14c9cb247"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54430.json"},{"type":"ADVISORY","url":"https://github.com/dedupeio/dedupe/security/advisories/GHSA-wrg3-xqw8-m85p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54430"},{"type":"FIX","url":"https://github.com/dedupeio/dedupe/commit/3f61e79102910bd355e920a2df7e44c14c9cb247"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dedupeio/dedupe","events":[{"introduced":"0"},{"fixed":"3f61e79102910bd355e920a2df7e44c14c9cb247"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.0.3","v3.0.2","v3.0.1","3.0.0","v2.0.24.redux","v2.0.24","v2.0.23","v2.0.22","v2.0.21.py.typed","v2.0.21","v2.0.20","v2.0.19","v2.0.18","v2.0.17","v2.0.16","v2.0.14","v2.0.13","v2.0.12","v2.0.11","v2.0.10","v2.0.9-longbuild","v2.0.9","v2.0.8","v2.0.7manylinux2","v2.0.7manylinux","v2.0.7","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2-retry-1","v2.0.2","v2.0.1","v2.0.0","test_github_actions_5","test_github_actions_4","test_github_actions_3","test_github_actions_2","test_github_actions_1","v1.10.0","v1.9.9","v1.9.7","v1.9.6","v1.9.5","v1.9.4","v1.9.3","v1.9.2forreal1","v1.9.1","v1.9.0","v1.8.2foreal","v1.8.2","v1.8.1","v1.8.0forreal","v1.8.0","v1.7.9","v1.7.8","v1.7.7","v1.7.6","v1.7.5","v1.7.4-forreal","v1.7.4","v1.7.3","1.7.2-forreal","v1.7.1","v1.7.0-appveyor","v1.7.0","v1.6.17","v1.6.15_manylinux","v1.6.15","v1.6.14-freal","v1.6.14","v1.6.13","v1.6.12","v1.6.11-forreal","v1.6.11","v1.6.10-manylinux","v1.6.10","v1.6.9","v1.6.7-retry","v1.6.7","v1.6.5","v1.6.4","v1.6.3","v1.6.2twine_deploy","v1.6.2sleepy","v1.6.2","v.1.6.1appveyormorepowershellfutzing","v.1.6.1appveyorpowershellfutzing","v.1.6.1appveyortwine","v1.6.1verboseappveyor","v1.6.1warehouse","v1.6.1","v.1.6.0py3.5","v1.6.0","v1.5.6fixpassword","v1.5.6fixtest","v1.5.6appveyor","v1.5.6","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.15","v1.4.14","v1.4.13","v1.4.11","v1.4.12","v1.4.10","v1.4.9","v1.4.8","v1.4.7a","v1.4.5","v1.4.6","v1.4.4","v1.4.3forreal","v1.4.3","v1.4.2","v1.4.1","v1.4.0","pypideploy2","v1.3.8appveyor1","v1.3.8","wide_windows_build","v1.0.0","v0.7.6.3","v0.7.5","v0.7.3","v0.7.1","v0.7.0","travislap","v0.6.0","v0.5.3.0","v0.5.2.1","v0.5.0.1","v0.5.0","v0.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54430.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}