Περιγραφή
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action-s entrypoint.sh invoked DangerJS from the caller-s workspace after copying the fork-s checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container in place of the action-s own code. This vulnerability is fixed in 1.0.1.
CVSS 8.2EPSS 0.181%Κίνδυνος 0.83
Προβολή πηγής- Δημοσίευση
- 2026-05-28 16:16:24
- Επηρεαζόμενες εκδόσεις
- <1.0.1
- Τύπος
- Άλλο
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N