Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
- Kynlos/CI-CD-Monitor-Test/.github/workflows/pr-bot.yml
Vulnerability:
- In job 'respond', step 'Answer question', an attacker-controlled Python script from the pull request is executed. The script '.github/scripts/answer-question.py' is checked out from the PR head in the 'Checkout PR code' step and then run, leading to arbitrary code execution.
Thank you for your time and for maintaining this project.
Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
Vulnerability:
Thank you for your time and for maintaining this project.