aayushxrj / aayushxrj/ai-sast-dast-pipeline-ci-cd

[Security] Security issue in your GitHub CI workflow YAML files

Open
#34 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Hello maintainers,

I would like to report a potential vulnerability in your GitHub CI workflows.

Affected files:
- aayushxrj/ai-sast-dast-pipeline-ci-cd/.github/workflows/dev-sast-pipeline.yml

Vulnerability:
- In job 'sast', steps 'Run Bandit on changed files (excluding tests/)' and 'Run Semgrep on changed files (excluding tests/)', the list of changed files from an attacker-controlled PR is spliced directly into the run shell via `${{ steps.changed-files.outputs.files }}', allowing command injection through malicious filenames.

Thank you for your time and for maintaining this project.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.