CVE-2025-53104 is a command injection vulnerability in the gluestack/gluestack-ui repository’s GitHub Actions workflow discussion-to-slack.yml, present prior to commit e6b4271. The vulnerable workflow processed untrusted GitHub Discussion fields such as title and body and directly interpolated those attacker-controlled values into shell commands within a run: block. Because the workflow was triggered on discussion creation, an attacker could submit a crafted discussion containing shell metacharacters or command substitution payloads such as $(curl ...), causing arbitrary commands to execute on the GitHub Actions runner. The issue was fixed by removing the vulnerable discussion-to-slack.yml workflow in commit e6b4271.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 100-file repository is an automated research snapshot of the gluestack-ui project, explicitly described in its README as a disposable laboratory artifact for reproducing public GitHub Actions workflow vulnerabilities. It is primarily a JavaScript/TypeScript React Native and Storybook UI repository, with GitHub Actions YAML workflows and a Python issue-assignment helper. It is not a conventional standalone exploit tool, but it contains a reproducible vulnerable workflow configuration. The security-relevant file is `.github/workflows/discussion-to-slack.yml`. On every newly created discussion, its `Get discussion details` shell step directly embeds untrusted discussion title, body, URL, author, and category expressions into `echo` commands. Because these values are not safely quoted or passed through a robust serializer, crafted discussion content can alter shell syntax and execute commands on the GitHub-hosted runner. These values are written to `$GITHUB_OUTPUT` and consumed by the following Slack notification action. The workflow exposes a Slack bot token only to the later action step; the vulnerable shell step does not explicitly receive that token. Other workflows perform normal CI testing against local Expo/Next.js servers, publishing, documentation dispatch, and GitHub issue/PR automation, and are ancillary to the primary finding.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.