CVE-2025-47775

MEDIUM

Bullfrog <0.8.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.

Scores

CVSS v3 6.2
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (2)
bullfrogsec/bullfrog < 0.8.4
GitHub Actions/bullfrogsec/bullfrog 0 - 0.8.4GitHub Actions
Published May 14, 2025
Tracked Since Feb 18, 2026