actions / actions/runner

Vulnerable npm Packages Present in GitHub Actions Runner

Open
#4,070 3 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C#
Stars
6.3k
Forks
1.4k
Avg merge
1d 16h
Merged PRs (30d)
24

Description

Describe the bug
We have identified multiple high and critical severity vulnerabilities reported by Prisma Cloud scans in our self-hosted GitHub Actions runner. Upon investigation, these vulnerabilities stem from npm packages bundled within the runner's environment, not from our application code. The used packages seems to be outdated versions and needs to be either upgraded to latest fixed version or they are just declared and not used at all in such case the declarations should be removed from respective package.json files.

Affected Packages

The following packages are declared in package.json files across nested submodules in the runner directory:

Package NameDeclared Version(s)CVEs Identifiedcodecov^1.0.1, ^3.8.2CVE-2020-15123, CVE-2020-7596, CVE-2020-7597minimist^1.2.5CVE-2021-44906| requirejs | ^2.1.16 | CVE-2024-38999 |
| async | ^3.2.0 | CVE-2021-43138 |
| cross-spawn | ^7.0.0, ^7.0.6 | CVE-2024-21538 |
| grunt | ^1.0.1, ^1.6.1 | CVE-2022-1537 |
| proxy | 2.1.1, 2.2.0 | CVE-2023-2968 |
| ws | ^3.3.3, ^5.2.4 | CVE-2024-37890 |
| vite | 5.2.11, 6.1.0 | CVE-2025-30208, CVE-2025-31125 |
| systeminformation | ^5.21.17 | CVE-2024-56334 |
| standard-version | ^7.0.0, ^9.5.0 | GHSA-7XCX-6WJH-7XP2 |

To Reproduce
Steps to reproduce the behavior:

  1. Create a self hosted runner using the action runner tarball
  2. Prisma scans report the above mentioned critical and high vulnerabilities against the packages given above.

Expected behavior
The used packages seems to be outdated versions and needs to be either upgraded to latest fixed version or they are just declared and not used at all in such case the declarations should be removed from respective package.json files.

Runner Version and Platform

Version of your runner? v2.328.0

OS of the machine running the runner? OSX/Windows/Linux/...
Linux

What's not working?

Attached Prisma scan report xls and npm command output for each pacakge

critical_high_vulnerabilities_report.csv

runner-vuln-analysis.txt

Job Log Output

If applicable, include the relevant part of the job / step log output here. All sensitive information should already be masked out, but please double-check before pasting here.

Runner and Worker's Diagnostic Logs

If applicable, add relevant diagnostic log information. Logs are located in the runner's _diag folder. The runner logs are prefixed with Runner_ and the worker logs are prefixed with Worker_. Each job run correlates to a worker log. All sensitive information should already be masked out, but please double-check before pasting here.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect the nested package.json files in the runner directory and compare their declared dependencies with critical_high_vulnerabilities_report.csv and runner-vuln-analysis.txt. Determine which listed packages are used, then verify that each used dependency is upgraded to a fixed version or that unused declarations are removed; rerun the npm analysis to confirm the reported vulnerabilities are addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.