Write-scoped repository token present inside a third-party build VM
Published · CVE: pending
Affected
The release build pipeline, for every release up to and including v0.5.0. No installed OgmaProtect software is affected.
Impact
Release packages were built inside a third-party OpenBSD VM image fetched at build time. The checkout step left a write-scoped repository token in the workspace, and the workspace was copied into that VM. Anything running inside the image, or anyone able to influence which image was fetched, could therefore have obtained write access to the product repository — a path to publishing a modified release. We have no evidence that this occurred. It is being disclosed because a supply-chain exposure in a product whose releases are meant to be trustworthy is worth stating plainly, whether or not it was exploited.
Remedy
No action is required on installed systems; the defect was in our build pipeline, not in the software. It was corrected on 2026-08-04: the checkout no longer persists credentials, and the workflow's permissions were narrowed. v0.5.1 is the first release built by the corrected pipeline, and also the first release we sign — so it is the first release whose provenance you can verify yourself. Verification instructions are on the download page.
Timeline
- Identified during an internal review of the release workflow; corrected the same day.
- Published, as part of the first end-to-end exercise of this disclosure channel.
Credit
Found internally during a review of the update and disclosure channel, 2026-08-04.
On the CVE state. We are not a CVE Numbering Authority. Where an identifier is warranted we request one from MITRE as an ordinary requester, which means it arrives on their timeline rather than ours. We publish the advisory when it is ready and update it in place once an identifier is assigned — we do not hold back a disclosure waiting for a number.