Skip to content

[security research] Test of CI handling for special filename - please close#2160

Closed
mohammadmseet-hue wants to merge 1 commit into
cdnjs:masterfrom
mohammadmseet-hue:probe-script-injection-test-h007
Closed

[security research] Test of CI handling for special filename - please close#2160
mohammadmseet-hue wants to merge 1 commit into
cdnjs:masterfrom
mohammadmseet-hue:probe-script-injection-test-h007

Conversation

@mohammadmseet-hue
Copy link
Copy Markdown
Contributor

Security research test PoC for a Cloudflare bug bounty submission demonstrating that the workflow's PR file-name handling is unsafe.

This PR adds a JSON file whose name contains a benign command substitution. The PR is intended only to surface the workflow run logs as evidence; it does not weaponize the substitution.

Please close without merging. Apologies for the noise. (Bug bounty report will be filed via HackerOne with proper details.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants