Repository navigation
[vulnhunter] VulnHunter findings in github/gh-aw #66044
Description
Activity
- addedcookieIssue Monster Loves Cookies!Issue Monster Loves Cookies!
on Oct 6, 2026 github-actions commented
on Oct 7, 2026 on Oct 7, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 28.3 AIC · ⌖ 10.3 AIC · ⊞ 13.2K · ◷
github-actions commented
on Oct 7, 2026 on Oct 7, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 15.1 AIC · ⌖ 8.78 AIC · ⊞ 13K · ◷
github-actions commented
on Oct 7, 2026 on Oct 7, 2026 – with GitHub ActionsContributorAuthorMore actionsCaution
agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.Details
Potential security threats were detected in the agent output.
Review the workflow run logs for details.
🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 19.7 AIC · ⌖ 14.8 AIC · ⊞ 12.9K · ◷
github-actions commented
on Oct 8, 2026 on Oct 8, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 21.1 AIC · ⌖ 8.92 AIC · ⊞ 14.3K · ◷
github-actions commented
on Oct 8, 2026 on Oct 8, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 12 AIC · ⌖ 9.76 AIC · ⊞ 14.5K · ◷
github-actions commented
on Oct 9, 2026 on Oct 9, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 15.8 AIC · ⌖ 8.87 AIC · ⊞ 14.1K · ◷
github-actions commented
on Oct 10, 2026 on Oct 10, 2026 – with GitHub ActionsContributorAuthorMore actions🍪 Issue Monster selected this for Copilot
I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.
If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.
Om nom nom! 🍪
🍪 Om nom nom by Issue Monster · pi · gpt54 · 11.3 AIC · ⌖ 8.53 AIC · ⊞ 14K · ◷
Reviewed against completed essentials issue #67454 (#67454) and merged PR #67475 (#67475).
The merged fix isolates inline graders in separate restricted Node processes, strips inherited environment capabilities, and adds regressions for process/require access and the reported command-execution escape.
Overview
A single-agent VulnHunter pass (Injection class, verified with adversarial falsification) over the pre-ranked scan scope surfaced one confirmed, PoC-verified finding: a complete sandbox-escape in the custom JavaScript grader runtime, bypassing both its static source blocklist and its Node
vmisolation to achieve arbitrary command execution.No other candidates in scope survived verification as exploitable — the Go CLI code (git/docker/grype/poutine/grant/remote-download command construction) is consistently hardened with argument-array
exec.Commandcalls, explicit ref/path validators (gitutil.ValidateGitRef/ValidateGitPath), and#nosecjustifications that checked out on review.Key finding
pkg/cli/graders_run.cjs(runInline) +pkg/workflow/graders_config.goblocklistVULN-001 — Grader script sandbox escape → arbitrary command execution (CWE-94)
Affected files / functions
pkg/cli/graders_run.cjs—runInline()(the "sandboxed" JS grader evaluator, embedded via(go/redacted):embedfrompkg/cli/graders_run.go:42)pkg/workflow/graders_config.go:454— theforbiddenPatternsstatic blocklist, the only other gate on this inputgh aw graders run <workflow> <grader-id> [run-id](pkg/cli/graders_command.go→pkg/cli/graders_run.go:66runGrader→runJavaScriptGrader)Attacker path / preconditions
A workflow's frontmatter can declare a custom (non-builtin, non-
operational-value) grader with an inlinescriptfield (graders.<id>.script).gh aw graders runstages the embeddedgraders_run.cjsand executes it with Node against that script. This command is the execution primitive behindgh-aw's trial/evaluation tooling (pkg/cli/trial_helpers.go), i.e. it is designed to run workflow-declared graders automatically against agent-run artifacts — plausibly in CI contexts holdingGH_TOKENand other secrets (seeactions/setup/js/validate_secrets.cjsfor the kind of secrets typically present alongside this tooling).Why it's exploitable
graders.<id>.scriptis a literal substring blocklist:require(,import(,import,fetch(,eval(,process.exit,child_process,execSync,spawnSync,Function(.graders_run.cjs::runInline()evaluates the script inside a Nodevmcontext whose sandbox nulls outprocess,require,Function,eval,global,globalThis, and setscodeGeneration: { strings: false, wasm: false }to block in-contexteval/Functionstring compilation.traceobject passed into that sandbox is built viastructuredClone(trace)in the host (unrestricted) Node realm, then onlyObject.freeze-deep-frozen. Freezing does not sever the prototype chain — any array/object insidetracestill resolves.constructorto the host realm'sArray/Function, which is not subject to the vm context'scodeGeneration.strings:falserestriction (that restriction binds to the context where code is compiled, not to functions reached via a leaked host-realm reference).Proof of concept (falsified against the exact blocklist from
graders_config.go— contains none of its literal substrings):Running this through a faithful reproduction of
runInline()prints:i.e. attacker-authored workflow configuration achieves full native command execution in the process running
gh aw graders run, defeating both the blocklist and the vm sandbox at once.Why this is a real security boundary, not a design assumption
The combined use of a frozen sandbox, nulled globals,
codeGeneration.strings:false, and a separate static blocklist whose own error message states "inline grader scripts must be pure functions without side effects" is explicit evidence the project intendsgraders.<id>.scriptto be treated as less-trusted, sandboxed input — not developer-equivalent-trust code.Remediation
vm+ a frozen global sandbox for untrusted code execution — Node's own docs state thevmmodule "is not a security mechanism." Use real isolation (separate process/container with no inherited secrets, or a proper engine such asisolated-vmconfigured to deep-copy — not just freeze — data entering the context).vmcontext must be constructed inside that context (e.g. viavm.runInContext(JSON.stringify(data), context)), so its prototype chain binds to the restricted realm rather than the host realm.Next actions
gh aw graders runexecutes it with live credentials.