References https://github.com/advisories/GHSA-f9xv-q969-pqx4 https://nvd.nist.gov/vuln/detail/CVE-2023-2251 https://www.miggo.io/vulnerability-database/cve/CVE-2023-2251 https://github.com/eemeli/yaml https://security.snyk.io/vuln/SNYK-JS-YAML-5458867 https://www.resolvedsecurity.com/vulnerability-catalog/CVE-2023-2251 https://security.alpinelinux.org/vuln/CVE-2023-2251
Related VulnerabilitiesPoCCVE-2024-9487: GitHub Enterprise - SAML Authentication BypassPoCCVE-2018-1000600: Jenkins GitHub Plugin <=1.29.1 - Server-Side Request ForgeryPoCCVE-2024-0200: Github Enterprise - Remote Code ExecutionPoCCVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token ExposurePoCgithub-gist-csp-bypass: Content-Security-Policy Bypass - GitHub GistPoCgithub-app-token: Github App TokenPoCgithub-oauth-token: Github OAuth Access TokenPoCgithub-personal-token: Github Personal TokenPoCgithub-refresh-token: Github Refresh TokenPoCgithub-login-check: Github Login CheckPoCappspec-yml-disclosure: Appspec YML/YAML - DetectPoCgithub-workflows-disclosure: Github Workflow DisclosurePoCgitlab-ci-yml: GitLab CI YAML - Exposure