CVE-2025-32953 affects z80pack, a multi-platform 8080/Z80 emulator, in version 1.38 and earlier. The vulnerable condition is in the makefile-ubuntu.yml GitHub Actions workflow, which uses actions/upload-artifact@v4 to upload the z80pack-ubuntu artifact. That artifact is created as a zip of the repository's current working directory, which includes the automatically generated .git/config file. During the workflow run, .git/config contains the run-scoped GITHUB_TOKEN. Because the artifact is downloadable before the workflow completes, there is a short time window in which an attacker can retrieve the artifact, extract the token from .git/config, and use it against the GitHub API. The issue was fixed in commit bd95916.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
GITHUB_TOKEN to an attacker. With that token, an attacker may be able to interact with the GitHub API using the permissions granted to the workflow, including pushing malicious code to the repository or rewriting release commits, resulting in repository integrity compromise and potential supply-chain impact. The practical impact depends on the token permissions configured for the workflow and repository.If you can’t patch tonight, do this now.
GITHUB_TOKEN permissions to the minimum required for the job, and avoid granting write permissions where not strictly necessary. Prevent artifacts from including .git/ content by explicitly selecting files/directories to archive. Review and rotate any tokens that may have been exposed, and inspect repository history, releases, and workflow activity for unauthorized pushes or rewritten commits.Patch, then assume compromise.
bd95916, which fixes the vulnerable workflow behavior. More generally, modify the GitHub Actions workflow so that uploaded artifacts do not include the repository metadata directory or any files containing credentials, especially .git/config. Ensure artifact packaging is restricted to explicit build outputs rather than the entire working directory.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.