.github/workflows/deploy-pipeline.yml:284:
const title = `${{ needs.verify-pr-checks.outputs.pr-title }}`;
pr-title is pr.title (set unsanitized at line 145) and is user-controlled. ${{ }} is substituted as text before the JavaScript is parsed, so a backtick, or a ${, in a PR title escapes the template literal and runs arbitrary JS in that step. The step has a pre-authenticated Octokit client available as github, and it runs in the same job that just used the Cloudflare deploy token.
title is declared and then never used: it appears zero times in the comment body below it (lines 286-297).
.github/workflows/deploy-pipeline.yml:284:const title = `${{ needs.verify-pr-checks.outputs.pr-title }}`;pr-titleispr.title(set unsanitized at line 145) and is user-controlled.${{ }}is substituted as text before the JavaScript is parsed, so a backtick, or a${, in a PR title escapes the template literal and runs arbitrary JS in that step. The step has a pre-authenticated Octokit client available asgithub, and it runs in the same job that just used the Cloudflare deploy token.titleis declared and then never used: it appears zero times in the comment body below it (lines 286-297).