4 ms·
Can you cite this? It's not YAML execution syntax, surely Github doesn't do it, the only vector I can see is if you put it unquoted into a shell script inside o
by CGamesPlay 5mo ago
Can you cite this? It's not YAML execution syntax, surely Github doesn't do it, the only vector I can see is if you put it unquoted into a shell script inside of a GHA yaml.
- theteapot 5mo agoI think he means template-injection -- https://woodruffw.github.io/zizmor/audits/#template-injection https://woodruffw.github.io/zizmor/audits/#template-injectio...
- benoau 5mo agoYes that's it.
- benoau 5mo agohttps://github.com/orgs/community/discussions/27065 https://github.com/orgs/community/discussions/27065 https://stackoverflow.com/questions/77090044/github-actions-adding-to-issue-title-breaking-with-backticks https://stackoverflow.com/questions/77090044/github-actions-... https://www.praetorian.com/blog/pwn-request-hacking-microsoft-github-repositories-and-more/ https://www.praetorian.com/blog/pwn-request-hacking-microsof... All you need is user content containing `backticked`, and a github action referencing that via eg "github.event.issue.title" where the shell would normally execute `backticked` as a command (like echo, cat, etc).