All findings

github-taskflow-accepted-no-cve-cluster high

GitHub Taskflow Agent yields 24 accepted reports without CVEs

Twenty-four Taskflow and GHSL-agent reports were publicly accepted or fixed across 23 no-CVE advisory pages covering twenty projects.

Bug class
SQL injection, attachment exfiltration, authorization bypass, action injection, and data exposure
Affected codebase
Twenty web applications, libraries, and GitHub Actions workflows
Credited system
GitHub Security Lab Taskflow Agent
Disclosed
May 22, 2026
Attribution
Direct source attribution
Severity
high
Source status: GitHub Security Lab publishes 23 no-CVE advisory pages containing 24 distinct reports. The pages use Taskflow-specific or generic GHSL AI-agent credits, GitHub's campaign articles connect both to Taskflow, and the affected projects accepted, published, or remediated the reports.

Summary

The first subset comprises nine accepted issues whose advisory pages explicitly name Taskflow Agent:

Fourteen additional advisory pages use GitHub Security Lab’s generic AI-agent credit and contain fifteen accepted or fixed reports:

Counting boundary

These are public, project-specific security reports with an acceptance or fix trail, so they satisfy Bugflation’s no-CVE rule. They are grouped as one campaign and do not increase the site’s unique-CVE counter. The page count is 23 while the report count is 24 because the ACL Anthology advisory contains two separate GHSL reports.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.