GHSL-2025-101: Code injection in a GitHub Actions workflow of homeassistant-tapo-control - CVE-2025-55192
Published Sep 11, 2025
·Updated
The homeassistant-tapo-control repository was vulnerable to code injection in the issues.yml GitHub Actions workflow.
Affected Software
1 affected component
Home Assistant homeassistant-tapo-control
Event History
Sep 11, 2025
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2025-101?
GHSL-2025-101 has a risk rating of 56, indicating a moderate level of severity.
2
How do I fix GHSL-2025-101?
To fix GHSL-2025-101, ensure that the GitHub Actions workflow in the issues.yml file is properly sanitized to prevent code injection.
3
What is the nature of the vulnerability in GHSL-2025-101?
GHSL-2025-101 involves a code injection vulnerability found in the GitHub Actions workflow of the homeassistant-tapo-control repository.
4
Which repository is affected by GHSL-2025-101?
GHSL-2025-101 affects the homeassistant-tapo-control repository used within Home Assistant.
5
When was GHSL-2025-101 published?
GHSL-2025-101 was published on September 11, 2025.