VDB
Sign up
HIGH7.9

GHSA-vqqr-rmpc-hhg2

melange pipeline working-directory could allow command injection

Quick fix

GHSA-vqqr-rmpc-hhg2 — chainguard.dev/melange: upgrade to the fixed version with the command below.

go get chainguard.dev/melange@v0.40.3

Details

An attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses `${{vars.*}}` or `${{inputs.*}}` substitutions in `working-directory`. The field is embedded into shell scripts without proper quote escaping.

**Fix:** Fixed with [e51ca30c](https://github.com/chainguard-dev/melange/commit/e51ca30cfb63178f5a86997d23d3fff0359fa6c8), Released.

**Acknowledgements**

melange thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/chainguard.dev/melange
Introduced in: 0.3.0Fixed in: 0.40.3
Fixgo get chainguard.dev/melange@v0.40.3

References