Vulnerabilities (CVE)

Filtered by vendor Fish-shop
Filtered by product Syntax-check
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42482 1 Fish-shop 1 Syntax-check 2024-09-17 N/A 6.5 MEDIUM
fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of the input value used in a workflow. This has the potential for exposure or exfiltration of sensitive information from the workflow runner, such as might be achieved by sending environment variables to ...

Show More