Confirmed release-input handling defect
Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2. Trigger requires permission to push a matching release tag; this is not an unauthenticated attack.
The release workflow extracts the tag into a step output, then interpolates that output directly into executable shell source inside a double-quoted sed command. Git tag names can contain shell command-substitution syntax.
Harmless local reproduction
git check-ref-format accepts a refs/tags/v1.2.3$(printf${IFS}INJECTED) ref.
- Substitute that version into the workflow's sed command and execute against a temporary pyproject fixture.
- The written version contains
1.2.3INJECTED, proving the substitution executed rather than being treated as literal data.
Independently reproduced by two reviewers. No tag was created or pushed, and no GitHub Actions job was dispatched.
The workflow grants write permissions and uses persisted checkout credentials. A malformed/untrusted tag string can therefore run code in the release job before normal packaging validation. A tag writer may already have other powerful repository rights, so this issue does not assert a new privilege boundary without repository-specific rules.
Acceptance criteria
- Pass tag/version via an environment variable or structured argument, never inline expression substitution into shell program text.
- Validate the intended version format before changing package metadata.
- Test command-substitution and sed-special characters as inert or rejected inputs.
- Keep valid release versions and the mandatory package smoke gate unchanged.
No source or workflow changes were made.
Confirmed release-input handling defect
Reviewed
masterat886c36d8ebe861aa987059a1744d45b78797baae(v4.7.0). Suggested priority: P2. Trigger requires permission to push a matching release tag; this is not an unauthenticated attack.The release workflow extracts the tag into a step output, then interpolates that output directly into executable shell source inside a double-quoted sed command. Git tag names can contain shell command-substitution syntax.
Harmless local reproduction
git check-ref-formataccepts arefs/tags/v1.2.3$(printf${IFS}INJECTED)ref.1.2.3INJECTED, proving the substitution executed rather than being treated as literal data.Independently reproduced by two reviewers. No tag was created or pushed, and no GitHub Actions job was dispatched.
The workflow grants write permissions and uses persisted checkout credentials. A malformed/untrusted tag string can therefore run code in the release job before normal packaging validation. A tag writer may already have other powerful repository rights, so this issue does not assert a new privilege boundary without repository-specific rules.
Acceptance criteria
No source or workflow changes were made.