CVE-2025-27616
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a specific set of headers and body data, an attacker could transfer ownership of a repository and its repo level secrets to a separate repository. These secrets could be exfiltrated by follow up builds to the repository. Users with an enabled repository with access to repo level CI secrets in Vela are vulnerable to the exploit, and any user with access to the CI instance and the linked source control manager can perform the exploit. Versions 0.25.3 and 0.26.3 fix the issue. No known workarounds are available.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.26%
- CWE
- CWE-290, CWE-345
- Published
- 2025-03-10
- Last modified
- 2026-03-13
Affected products
- go-vela server
- go-vela server
Weakness type
Related vulnerabilities
- CVE-2026-82563 — Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing
- CVE-2026-82530 — IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
- CVE-2026-62759 — Windows Netlogon Spoofing Vulnerability
- CVE-2026-86478 — In JetBrains YouTrack before 2025.3.161254,...
- CVE-2026-84186 — Incorrect access control in PrestaShop
- CVE-2026-86196 — Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
- CVE-2026-85432 — MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity
- CVE-2026-84766 — WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability