CVE-2025-47775

MEDIUM

Bullfrog <0.8.4 - Privilege Escalation

Title source: llm

Description

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.

Scores

CVSS v3 6.2
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-201
Status published

Affected Products (2)

bullfrogsec/bullfrog < 0.8.4
GitHub Actions/bullfrogsec/bullfrog < 0.8.4GitHub Actions

Timeline

Published May 14, 2025
Tracked Since Feb 18, 2026