CodeQL Product Security Update Advisory (CVE-2025-24362)
Overview
We have released a security update to address a vulnerability in our CodeQL products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-24362
CodeQL Action 3.26.11 and later versions before 3.28.2
CodeQL Action 2.26.11 and later versions before 3
CodeQL CLI versions 2.9.2 or later but earlier than 2.20.3
Resolved Vulnerabilities
Sensitive Information Clear Disclosure Vulnerability via Environment Variables (CVE-2025-24362)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-24362
CodeQL Action version 3.28.3
CodeQL CLI version 2.20.3
References
[1] GitHub PAT written to debug artifacts
https://github.com/github/codeql-action/security/advisories/GHSA-vqf5-2xx6-9wfm