Skip to content

Verify branch-based workflow script injections don't work #2

Open
@SIMULATAN

Description

Including code in the branch name and triggering a workflow run may result in arbitrary command execution due to github's templates not being escaped automatically.

See GHSA-7x29-qqmq-v6qc

Metadata

Assignees

Labels

Type

No type

Projects

  • Status

    Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions