Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
- ModularGroup/scratch-id/.github/workflows/summary.yml
Vulnerability:
- In job 'summary', the attacker-controlled LLM response '${{ steps.inference.outputs.response }}' from step 'Run AI inference' is spliced into the run shell in step 'Comment with AI summary'; the attacker-controlled source is 'github.event.issue.title' and 'github.event.issue.body' used in the LLM prompt.
Thank you for your time and for maintaining this project.
Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
Vulnerability:
Thank you for your time and for maintaining this project.