Junglewise Threat Intelligence

CVE-2022-35954: @actions/core delimiter injection in exportVariable

CVE-2022-35954 · Severity: low · CVSS 3.1 · Published 2022-08-18

Vendors: GitHub, npm.

Executive brief

@actions/core is a JavaScript library that GitHub Actions workflows use to interact with the CI/CD environment, including setting environment variables. A delimiter injection vulnerability in the exportVariable function allows attackers to break out of a single variable assignment and modify arbitrary environment variables, which could alter workflow behavior or expose sensitive information if untrusted input is written to the environment.

Technical details

The exportVariable function in @actions/core uses a predictable delimiter (_GitHubActionsFileCommandDelimeter_) to parse and write environment variables to the GITHUB_ENV file. An attacker who controls input passed to exportVariable can inject this delimiter to escape the current variable assignment and inject additional variable definitions. This is a classic delimiter injection / command injection vulnerability (CWE-74, CWE-77). The attack requires that a workflow calls exportVariable with untrusted user-controlled data; no authentication bypass or local privilege is needed if the attacker can influence workflow inputs. The vulnerability was patched in version 1.9.1 by properly escaping the delimiter value.

Affected products

  • GitHub @actions/core <= 1.9.0

Timeline

  • 2022-08-18: disclosed: GHSA-7r3h-m5j6-3q42 published
  • 2022-08-18: patched: Version 1.9.1 released with fix

References

Related threats