npm package report

Is @actions/core safe?

2 known vulnerabilities, worst severity MODERATE.

cvss
5.0

how bad it is if exploited, out of 10

epss
0.70%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-7r3h-m5j6-3q42, the advisory selected below

// advisories

GHSA-7r3h-m5j6-3q42

MODERATECVE-2022-35954

The core.exportVariable function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the GITHUBENV file may cause the path or other environment variables to be modified without the intention of the workflow or action author.

Affected
<= 1.9.0
Fixed in
1.9.1
Weakness
CWE-74
Published
2022-08-18
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:50 UTC. The most recent advisory here was published 2022-08-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @actions/core safe? npm package security report | CyberXYZ