{"id":"CVE-2023-52137","summary":"GitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames","details":"The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution. This could potentially allow filenames that contain special characters such as `;` which can be used by an attacker to take over the [GitHub Runner](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners) if the output value is used in a raw fashion (thus being directly replaced before execution) inside a `run` block. By running custom commands, an attacker may be able to steal secrets such as `GITHUB_TOKEN` if triggered on other events than `pull_request`.\n\nThis has been patched in versions [17](https://github.com/tj-actions/verify-changed-files/releases/tag/v17) and [17.0.0](https://github.com/tj-actions/verify-changed-files/releases/tag/v17.0.0) by enabling `safe_output` by default and returning filename paths escaping special characters for bash environments.","aliases":["GHSA-ghm2-rq8q-wrhc"],"modified":"2026-08-12T03:51:12.217487170Z","published":"2023-12-29T17:08:49.356Z","database_specific":{"cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52137.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52137.json"},{"type":"ADVISORY","url":"https://github.com/tj-actions/verify-changed-files/security/advisories/GHSA-ghm2-rq8q-wrhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-52137"},{"type":"FIX","url":"https://github.com/tj-actions/verify-changed-files/commit/498d3f316f501aa72485060e8c96fde7b2014f12"},{"type":"FIX","url":"https://github.com/tj-actions/verify-changed-files/commit/592e305da041c09a009afa4a43c97d889bed65c3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tj-actions/verify-changed-files","events":[{"introduced":"0"},{"fixed":"bc950d8b56b01c2c024b82bf5b8f93b685713725"},{"fixed":"498d3f316f501aa72485060e8c96fde7b2014f12"},{"fixed":"592e305da041c09a009afa4a43c97d889bed65c3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"17.0.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:tj-actions:verify-changed-files:*:*:*:*:*:github:*:*"}}],"versions":["v16.1.1","v16","v16.1.0","v16.0.1","v16.0.0","v15.0.2","v15","v15.0.1","v15.0.0","v14.0.2","v14","v14.0.1","v14.0.0","v13.2.0","v13","v13.1","v12.0","v12","v11.1","v11","v10.1","v10","v9.2","v9.1","v9","v8.8","v8.7","v8.6","v8.5","v8.4","v8.3","v8.2","v8.1","v8","v7.2","v7.1","v7","v6.2","v6.1","v6","v5.7","v5.6","v5.5","v5.4","v5.3","v5.2","v5.1","v5","v4","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.gamma","v3.0.beta","v3.0.alpha","v3.0.g","v3.0.b","v3.0.a","v3","v2.0a","v1.0.1","v2","v1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-52137.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L"}]}