Exposure of server configuration in github.com/go-vela/serverGHSA-gv2h-gf8m-r68j
HIGHFix: go-vela/compiler@f1ace5fGHSA-gv2h-gf8m-r68j is a high-severity (CVSS 7.4) OS Command Injection vulnerability in github.com/go-vela/compiler. 1 public exploit reference exists, so weaponization risk is real. A fix is available for github.com/go-vela/compiler — see the affected versions and patch details below.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-gv2h-gf8m-r68j by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
github.com/go-vela/compilerReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.
Description
Impact
What kind of vulnerability is it? Who is impacted?
- The ability to expose configuration set in the Vela server via pipeline template functionality.
- It impacts all users of Vela.
Sample of template exposing server configuration using Sprig's env function:
metadata:
template: true
steps:
- name: sample
image: alpine:latest
commands:
# OAuth client ID for Vela <-> GitHub communication
- echo {{ env "VELA_SOURCE_CLIENT" }}
# secret used for server <-> worker communication
- echo {{ env "VELA_SECRET" }}
Patches
Has the problem been patched? What versions should users upgrade to?
- Upgrade to
0.6.1
Additional Recommended Action(s)
- Rotate all secrets
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
- No
For more information
If you have any questions or comments about this advisory:
- Email us at [email protected]
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐹Go | github.com/go-vela/compiler | all versions | 0.6.1go get github.com/go-vela/compiler@v0.6.1 |
Affected Products
compilertargetResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/go-vela/compiler, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update github.com/go-vela/compiler to 0.6.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-gv2h-gf8m-r68j is resolved across your whole dependency graph.
Workarounds
Stop passing untrusted input into the interpreter or shell: call the affected binary with an argument array rather than a composed command string, reject anything outside a strict allowlist of expected values, and run the component under an account that cannot reach beyond the work it legitimately does.
Frequently Asked Questions
Is GHSA-gv2h-gf8m-r68j in your dependencies?
Find it across Go, including transitive dependencies.