Impact
What kind of vulnerability is it? Who is impacted?
An attacker can use a malicious issue comment to execute RCE with the issues: write
permission, giving them full control over the issues in the repository.
Patches
Has the problem been patched? What versions should users upgrade to?
Patches have been applied to the production version of the workflow.
Credits
This security concern was identified by Aviv Keller.
Impact
What kind of vulnerability is it? Who is impacted?
An attacker can use a malicious issue comment to execute RCE with the
issues: write
permission, giving them full control over the issues in the repository.Patches
Has the problem been patched? What versions should users upgrade to?
Patches have been applied to the production version of the workflow.
Credits
This security concern was identified by Aviv Keller.