Skip to content

[GHSA-4xqx-pqpj-9fqw] gajira-create GitHub action vulnerable to arbitrary code execution - #9641

Open
sharadverma638 wants to merge 1 commit into
sharadverma638/advisory-improvement-9641from
sharadverma638-GHSA-4xqx-pqpj-9fqw
Open

sharadverma638 wants to merge 1 commit into
sharadverma638/advisory-improvement-9641from
sharadverma638-GHSA-4xqx-pqpj-9fqw

Conversation

@sharadverma638

Copy link
Copy Markdown

Updates

  • CWEs

Comments
This advisory has no CWE assigned. Per GitHub Security Lab's GHSL-2020-172, the action's undocumented {{ }} template syntax passes user-controlled summary and description inputs to lodash _.template, so they are evaluated as JavaScript. This is code injection via a template engine. The CVE record also lists the problem type as "Template Injection." Suggesting CWE-94 and CWE-1336.

@github-actions
github-actions Bot changed the base branch from main to sharadverma638/advisory-improvement-9641 September 20, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant