PT-2026-106219 · Chainguard Academy · Integrate-Platform-Docs
CVSS v3.1
3.3
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chainguard Academy (edu) integrate-platform-docs composite GitHub Action versions from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff through commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3
Description
Improper neutralization of special elements used in an OS command allows an actor who controls the
project id or storage bucket inputs to execute arbitrary shell commands on the GitHub Actions runner. This occurs because these inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions.Recommendations
Update the integrate-platform-docs composite GitHub Action to commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Integrate-Platform-Docs