{"id":"CVE-2026-105767","summary":"Chainguard Academy (edu) integrate-platform-docs composite action interpolates inputs into shell commands","details":"Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps.","modified":"2026-10-08T02:49:19.827421100Z","published":"2026-10-05T19:48:47.712Z","database_specific":{"cna_assigner":"chainguard","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105767.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105767.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105767"},{"type":"FIX","url":"https://github.com/chainguard-dev/edu/commit/fb0efb2537d326ab18c07d620875b8ed2a4b39f3"},{"type":"FIX","url":"https://github.com/chainguard-dev/edu/pull/3471"},{"type":"PACKAGE","url":"https://github.com/chainguard-dev/edu"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/chainguard-dev/edu","events":[{"introduced":"7375a80caabcc31c33ec90f29687ed78c13d16ff"},{"fixed":"fb0efb2537d326ab18c07d620875b8ed2a4b39f3"}],"database_specific":{"source":"REFERENCES"}}],"versions":["ai-docs-20260430-121310","ai-docs-20260429-150259","ai-docs-20260429-134421","ai-docs-20260429-133408","ai-docs-20260428-132624","ai-docs-20260428-120411","ai-docs-20260427-135041","ai-docs-20260427-125209","ai-docs-20260427-122413","ai-docs-20260426-030135","ai-docs-20260426-021819","ai-docs-20260424-122346","ai-docs-20260423-185744","ai-docs-20260423-182027","ai-docs-bundle","ai-docs-latest","ai-docs"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105767.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}