CVE-2025-47775
MEDIUMBullfrog <0.8.4 - Privilege Escalation
Title source: llmDescription
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.
Scores
CVSS v3
6.2
EPSS
0.0011
EPSS Percentile
29.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-201
Status
published
Affected Products (2)
bullfrogsec/bullfrog
< 0.8.4
GitHub Actions/bullfrogsec/bullfrog
< 0.8.4GitHub Actions
Timeline
Published
May 14, 2025
Tracked Since
Feb 18, 2026