3 ms·
What in the world? The security advisory was published to their repo 4 months ago? EDIT: Oh... Apparantly they reintroduced the vuln again about a month later.
by nulld3v 2y ago
What in the world? The security advisory was published to their repo 4 months ago?
EDIT: Oh... Apparantly they reintroduced the vuln again about a month later... https://github.com/ultralytics/actions/commit/5f84281dad900e7ab4e11c16d8b85d1ed58c88a7 https://github.com/ultralytics/actions/commit/5f84281dad900e...
I'm guessing that workflow is still vulnerable. Surely piping user-controlled text into the .env file for your runner should raise some red flags?
- never_inline 2y agoWhy does it run in the context of base branch though?
- alilleybrinker 2y agoThe repository maintainers are running actions for PRs with the `pull_request_target` trigger, which gives full access to target repository secrets with write permissions. It's very explicitly documented as dangerous to do this. To mitigate the risk, `pull_request_target` actions run on the state of the target branch, not the source branch, but in this case because the target branch has this script which executes code influenced by an untrusted data source (the branch name), you get this vulnerability.