Argos JavaScript 提供官方的 Argos JavaScript SDK。在 Argos core 包 6.2.1 版本之前,攻击者可控的 CI 分支或引用值(来自 或 )会在 为 时,通过 和 传递。 中的 和 函数会将这些值插入到由 执行的 命令字符串中。因此,如果拉取请求(pull-request)的分支名中包含 shell 元字符,攻击者可以利用这一漏洞以 Argos 上传流程的权限在 CI 运行器上执行任意命令。成功利用该漏洞可能导致 CI 密钥泄露、构建产物被篡改或运行器被入侵。此问题已在
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| argos-ci | argos-javascript | < 6.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| argos-ci | argos-javascript | < 6.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet