Vulnerability Description
The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code. This is patched in 1.13.6. As a workaround, one may downgrade to a version prior to 1.13.2.
Related Weaknesses (CWE)
References
- https://github.com/OZI-Project/publish/commit/abd8524ec69800890529846b3ccfb09ce7
- https://github.com/OZI-Project/publish/security/advisories/GHSA-2487-9f55-2vg9
FAQ
What is CVE-2025-47271?
CVE-2025-47271 is a documented vulnerability. The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted d...
How severe is CVE-2025-47271?
CVSS scoring is not yet available for CVE-2025-47271. Check NVD for updates.
Is there a patch for CVE-2025-47271?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.