Skip to content

PR title is interpolated into a github-script template literal #202

Description

@0rbitingZer0

.github/workflows/deploy-pipeline.yml:284:

const title = `${{ needs.verify-pr-checks.outputs.pr-title }}`;

pr-title is pr.title (set unsanitized at line 145) and is user-controlled. ${{ }} is substituted as text before the JavaScript is parsed, so a backtick, or a ${, in a PR title escapes the template literal and runs arbitrary JS in that step. The step has a pre-authenticated Octokit client available as github, and it runs in the same job that just used the Cloudflare deploy token.

title is declared and then never used: it appears zero times in the comment body below it (lines 286-297).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions