Skip to content

Actions expression injection in `helpers/version/action.yml`

Low
frenck published GHSA-jff5-5j3g-vhqc Oct 19, 2023

Package

actions home-assistant/actions/helpers/version (GitHub Actions)

Affected versions

< September 5, 2023

Patched versions

September 5, 2023

Description

The GitHub Security Lab team has identified a potential security vulnerability in Home Assistant's GitHub Actions.

Summary

The home-assistant/actions helpers/version workflow is vulnerable to a command injection in GitHub Actions, allowing an attacker to leak secrets and alter the repository using the workflow potentially.

Credit

This issue was discovered and reported by GHSL team members @jorgectf (Jorge) and @p- (Peter Stöckli).

GitHub Security Lab (GHSL) Vulnerability Report: GHSL-2023-179

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits