CVE-2025-15617 | Wazuh 4.12.0 GitHub Action GITHUB_TOKEN insufficiently protected credentials (GHSA-6xqr-4q5g-xc7x)
A vulnerability has been found in Wazuh 4.12.0 and classified as problematic. Impacted is an unknown function of the component GitHub Action Handler. This manipulation of the argument GITHUB_TOKEN causes insufficiently protected credentials.
This vulnerability is tracked as CVE-2025-15617. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.