What in the world? The security advisory was published to their repo 4 months ago?
EDIT: Oh... Apparantly they reintroduced the vuln again about a month later... https://github.com/ultralytics/actions/commit/5f84281dad900e...
I'm guessing that workflow is still vulnerable. Surely piping user-controlled text into the .env file for your runner should raise some red flags?