CVE-2025-47775

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/05/2025
Last modified:
11/07/2025

Description

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bullfrogsec:bullfrog:*:*:*:*:*:*:*:* 0.8.4 (excluding)