CVE-2025-47775HIGH 8.6EPSS p31.5%
CVE-2025-47775CVE-2025-47775
Description
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.
Scoring
| CVSS 3.1 | 8.6 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.40% probability of exploitation · percentile 31.5% · 2026-06-19T12:03:05Z |
| Published | 2025-05-14 |
| Last modified | 2025-07-11 |
Underlying weaknesses· 1
References
- https://github.com/bullfrogsec/bullfrog/commit/ae7744ae4b3a6f8ffc2e49f501e30bf1a43d4671
- https://github.com/bullfrogsec/bullfrog/releases/tag/v0.8.4
- https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3
- https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insertion of Sensitive Information Into Sent Datacwe-201 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.