[GH-ISSUE #1553] Github Security Lab: GHSL-2023-004 #782

Closed
opened 2026-03-01 21:46:18 +03:00 by kerem · 2 comments
Owner

Originally created by @Kwstubbs on GitHub (Jan 10, 2023).
Original GitHub issue: https://github.com/nektos/act/issues/1553

Bug report info

The GitHub Security Lab team has identified a potential security vulnerability in act.
We have sent a security report to cplee@nektos.com on January 9, 2023 as there was no published security contact.
Please let us know if there is a better point of contact for security issues. We highly recommend sending security reports over a private communication channel.

Command used with act

Private

Describe issue

Private

No response

Workflow content

Private

Relevant log output

Private

Additional information

No response

Originally created by @Kwstubbs on GitHub (Jan 10, 2023). Original GitHub issue: https://github.com/nektos/act/issues/1553 ### Bug report info The GitHub Security Lab team has identified a potential security vulnerability in act. We have sent a security report to cplee@nektos.com on January 9, 2023 as there was no published security contact. Please let us know if there is a better point of contact for security issues. We highly recommend sending security reports over a private communication channel. ### Command used with act ```sh Private ``` ### Describe issue Private ### Link to GitHub repository _No response_ ### Workflow content ```yml Private ``` ### Relevant log output ```sh Private ``` ### Additional information _No response_
kerem 2026-03-01 21:46:18 +03:00
  • closed this issue
  • added the
    kind/bug
    label
Author
Owner

@cplee commented on GitHub (Jan 10, 2023):

@Kwstubbs - i received your email and will follow up over private channel.

<!-- gh-comment-id:1377808868 --> @cplee commented on GitHub (Jan 10, 2023): @Kwstubbs - i received your email and will follow up over private channel.
Author
Owner

@cplee commented on GitHub (Jan 16, 2023):

Fixed in #1565

<!-- gh-comment-id:1384577842 --> @cplee commented on GitHub (Jan 16, 2023): Fixed in #1565
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/act#782
No description provided.