{"id":"GHSA-ghm2-rq8q-wrhc","summary":"Potential Actions command injection in output filenames (GHSL-2023-275)","details":"### Summary\nThe [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets.\n\n### Details\nThe [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution.\n\nThis could potentially allow filenames that contain special characters such as `;` and \\` (backtick) which can be used by an attacker to take over the [GitHub Runner](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners) if the output value is used in a raw fashion (thus being directly replaced before execution) inside a `run` block. By running custom commands an attacker may be able to steal **secrets** such as `GITHUB_TOKEN` if triggered on other events than `pull_request`. For example on `push`.\n\n#### Proof of Concept\n\n1. Submit a pull request to the repository with a new file injecting a command. For example `$(whoami).txt` would be a valid filename.\n2. Upon approval of the workflow (triggered by the pull request), the action will get executed and the malicious pull request filename will flow into the `List all changed files tracked and untracked files` step.\n\n```yaml\n- name: List all changed files tracked and untracked files\n  run: |\n    echo \"Changed files: ${{ steps.verify-changed-files.outputs.changed_files }}\"\n```\n\nExample output:\n\n```yaml\n##[group]Run echo \"Changed files: $(whoami).txt\"\n  echo \"Changed files: $(whoami).txt\"\u001b[0m\nshell: /usr/bin/bash -e {0}\n##[endgroup]\nChanged files: runner.txt\n```\n\n### Impact\nThis issue may lead to arbitrary command execution in the GitHub Runner.\n\n### Resolution\n- A new `safe_output` input would be enabled by default and return filename paths escaping special characters like ;, ` (backtick), $, (), etc for bash environments.\n\n- A safe recommendation of using environment variables to store unsafe outputs.\n\n```yaml\n- name: List all changed files tracked and untracked files\n  env:\n     CHANGED_FILES: ${{ steps.verify-changed-files.outputs.changed_files }}\n  run: |\n    echo \"Changed files: $CHANGED_FILES\"\n```\n\n\n### Resources\n\n* [Keeping your GitHub Actions and workflows secure Part 2: Untrusted input](https://securitylab.github.com/research/github-actions-untrusted-input/)\n* [Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)\n","aliases":["CVE-2023-52137"],"modified":"2026-09-15T06:33:59.292404649Z","published":"2024-01-02T16:42:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-01-02T16:42:27Z","nvd_published_at":"2023-12-29T17:16:07Z","cwe_ids":["CWE-20","CWE-77"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/tj-actions/verify-changed-files/security/advisories/GHSA-ghm2-rq8q-wrhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-52137"},{"type":"WEB","url":"https://github.com/tj-actions/verify-changed-files/commit/498d3f316f501aa72485060e8c96fde7b2014f12"},{"type":"WEB","url":"https://github.com/tj-actions/verify-changed-files/commit/592e305da041c09a009afa4a43c97d889bed65c3"},{"type":"PACKAGE","url":"https://github.com/tj-actions/verify-changed-files"}],"affected":[{"package":{"name":"tj-actions/verify-changed-files","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17"}]},{"type":"GIT","repo":"https://github.com/tj-actions/verify-changed-files","events":[{"introduced":"0"},{"fixed":"2acec78834cc690f70b3445712363fc314224127"}]}],"versions":["v17.0.2","v17.0.1","v17.0.0","v16.1.1","v16","v16.1.0","v16.0.1","v16.0.0","v15.0.2","v15","v15.0.1","v15.0.0","v14.0.2","v14","v14.0.1","v14.0.0","v13.2.0","v13","v13.1","v12.0","v12","v11.1","v11","v10.1","v10","v9.2","v9.1","v9","v8.8","v8.7","v8.6","v8.5","v8.4","v8.3","v8.2","v8.1","v8","v7.2","v7.1","v7","v6.2","v6.1","v6","v5.7","v5.6","v5.5","v5.4","v5.3","v5.2","v5.1","v5","v4","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.gamma","v3.0.beta","v3.0.alpha","v3.0.g","v3.0.b","v3.0.a","v3","v2.0a","v1.0.1","v2","v1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-ghm2-rq8q-wrhc/GHSA-ghm2-rq8q-wrhc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L"}]}