Web Hack List

Collected research

GHSL-2024-312: Arbitrary code execution and secret exfiltration in Azure API Management Developer Portal

A GitHub Actions workflow echoed the JSON of every open issue into a file through Bash interpolation. Anyone who opens an issue whose title or body contains backticks breaks out of the quoting and runs commands on the runner, capturing the workflow token and its secrets.

Record

Researcher
pwntester and @pwntester
Published by
GitHub Security Lab
Date
Format
Advisory
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pwntester and @pwntester, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .