Skip to content

Maven workflow vulnerability: unsafe interpolation of github.ref_name into shell API URL #1494

Description

@gemshrine

Symptom

The Maven notification workflow interpolates github.ref_name directly into the gh api URL used to find previous runs.

Steps to reproduce

  1. Start .github/workflows/mvn.yml for a branch or tag containing shell metacharacters, such as test$(touch /tmp/marker).
  2. Inspect the previous step's gh api command.

Actual result

The expression is expanded before Bash parses the command. Command substitution in the resulting double-quoted URL can run arbitrary commands in the workflow.

Expected result

Use an environment variable or a request parameter for the ref and validate it before constructing the API query.

Evidence

.github/workflows/mvn.yml:86 contains branch=${{ github.ref_name }} inside a shell command.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggood-titleThe title was checked and improved by ChatGPT

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions