GHSA-vqqr-rmpc-hhg2
melange pipeline working-directory could allow command injection
Quick fix
GHSA-vqqr-rmpc-hhg2 — chainguard.dev/melange: upgrade to the fixed version with the command below.
go get chainguard.dev/melange@v0.40.3Details
An attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses `${{vars.*}}` or `${{inputs.*}}` substitutions in `working-directory`. The field is embedded into shell scripts without proper quote escaping.
**Fix:** Fixed with [e51ca30c](https://github.com/chainguard-dev/melange/commit/e51ca30cfb63178f5a86997d23d3fff0359fa6c8), Released.
**Acknowledgements**
melange thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.3.0Fixed in: 0.40.3go get chainguard.dev/melange@v0.40.3