CodeQL Product Security Update Advisory (CVE-2025-24362)

CodeQL Product Security Update Advisory (CVE-2025-24362)

Overview

 

We have released a security update to address a vulnerability in our CodeQL products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-24362

 

CodeQL Action 3.26.11 and later versions before 3.28.2
CodeQL Action 2.26.11 and later versions before 3
CodeQL CLI versions 2.9.2 or later but earlier than 2.20.3

 

 

Resolved Vulnerabilities

 

Sensitive Information Clear Disclosure Vulnerability via Environment Variables (CVE-2025-24362)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

 

CVE-2025-24362

 

CodeQL Action version 3.28.3
CodeQL CLI version 2.20.3

 

 

References

 

[1] GitHub PAT written to debug artifacts
https://github.com/github/codeql-action/security/advisories/GHSA-vqf5-2xx6-9wfm