serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and github.head_ref, to a command in the runner. Due to the action using the pull_request_target trigger it has permissive permissions by default. An unauthorized attacker can exploit this vulnerability to push arbitrary data to the repository. The subsequent impact on the end-user is executing the attackers' code when running serverless-dns. This is fixed in commit c5537dd, and expected to be released in 0.1.31.
History

Tue, 30 Sep 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Serverless-dns
Serverless-dns serverless-dns
Vendors & Products Serverless-dns
Serverless-dns serverless-dns

Tue, 30 Sep 2025 00:45:00 +0000

Type Values Removed Values Added
Description serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and github.head_ref, to a command in the runner. Due to the action using the pull_request_target trigger it has permissive permissions by default. An unauthorized attacker can exploit this vulnerability to push arbitrary data to the repository. The subsequent impact on the end-user is executing the attackers' code when running serverless-dns. This is fixed in commit c5537dd, and expected to be released in 0.1.31.
Title serverless-dns is vulnerable to Command Injection through pr.yml GitHub Action Workflow
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-30T00:12:23.873Z

Updated: 2025-09-30T00:12:23.873Z

Reserved: 2025-09-26T16:25:25.150Z

Link: CVE-2025-61584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-30T11:37:41.910

Modified: 2025-09-30T11:37:41.910

Link: CVE-2025-61584

cve-icon Redhat

No data.