Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

nektos — Vulnerabilities & Security Advisories 3

Browse all 3 CVE security advisories affecting nektos. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nektos is a CLI tool for automating software development workflows, primarily used for GitHub Actions and other CI/CD pipelines. Historically, it has been susceptible to remote code execution vulnerabilities due to unsafe deserialization and command injection flaws, as well as privilege escalation issues through improper handling of environment variables. The project has addressed three CVEs to date, including RCE vulnerabilities in its YAML parsing and argument handling components. While no major public security incidents have been documented, the consistent presence of RCE flaws in its history suggests potential risks for organizations using the tool in production environments without proper input validation and sandboxing measures.

Top products by nektos: act

This page lists every published CVE security advisory associated with nektos. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.