Vulnerabilities > TJ Actions > Verify Changed Files

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-52137 Command Injection vulnerability in Tj-Actions Verify-Changed-Files
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets.
network
low complexity
tj-actions CWE-77
8.8