VulnerabilityAnalyzed
CVE-2025-47775
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows.
HIGH 8.6EPSS 0.47%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-201
- Affected
- bullfrogsec/bullfrog
- Source
- security-advisories@github.com
References
- https://github.com/bullfrogsec/bullfrog/commit/ae7744ae4b3a6f8ffc2e49f501e30bf1a43d4671Patch
- https://github.com/bullfrogsec/bullfrog/releases/tag/v0.8.4Release Notes
- https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3Exploit, Vendor Advisory
- https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.