Collected research
GHSL-2024-312: Arbitrary code execution and secret exfiltration in Azure API Management Developer Portal
A GitHub Actions workflow echoed the JSON of every open issue into a file through Bash interpolation. Anyone who opens an issue whose title or body contains backticks breaks out of the quoting and runs commands on the runner, capturing the workflow token and its secrets.
Record
- Researcher
- pwntester and @pwntester
- Published by
- GitHub Security Lab
- Date
- Format
- Advisory
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pwntester and @pwntester, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .