Skip to content

[sighthound] Security findings in github/gh-aw #64924

Description

@github-actions

Top Sighthound findings (from actionable.json):

  • /pkg/workflow/js/close_issue.cjs — Critical (Command Injection, CWE-78). User-controlled params taint reaches exec (line 53). Remediation: avoid shell execution for user input; use argument arrays (spawn/execFile) with strict allowlists and validation.
  • /pkg/workflow/js/close_issue.cjs — Critical (Command Injection, CWE-78). Taint flow to exec (line 6) in asShellArg path. Remediation: remove shell-string construction, use structured command invocation, and reject unsafe metacharacters.
  • /actions/setup/js/close_issue.cjs — Critical (Command Injection, CWE-78). User params reaches exec (line 53). Remediation: same hardening as above; centralize safe command wrapper and input schema checks.
  • /actions/setup/js/close_issue.cjs — Critical (Command Injection, CWE-78). Additional taint path to exec (line 6). Remediation: eliminate shell interpolation helpers and pass only validated, typed arguments.
  • /pkg/cli/bootstrap_profile_helpers.go — High (Code Injection/SSTI, CWE-94). Dynamic template parse via template.New(...).Parse(bootstrapRegistrationPageTmpl) (line 262). Remediation: keep templates static/embedded and pass untrusted values only as escaped data into template execution.

Notes:

  • These were selected as the highest-severity findings (Critical/High) from actionable.json.
  • Prioritize fixing command-injection sinks first due to direct command execution risk.

Generated by 🛡️ Sighthound Security Scan · codex · gpt53codex · 6.21 AIC · ⌖ 2.67 AIC · ⊞ 18.6K · ◷

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions