Skip to content

fix: prevent shell injection through GitLab inputs - #193

Merged
fengmk2 merged 1 commit into
mainfrom
fix/gitlab-input-shell-injection
Oct 10, 2026
Merged

fengmk2 merged 1 commit into
mainfrom
fix/gitlab-input-shell-injection

Conversation

@fengmk2

@fengmk2 fengmk2 commented Oct 8, 2026

Copy link
Copy Markdown
Member

GitLab string inputs can close fixed shell delimiters and run commands before the runtime checks their values. This affects pipelines that accept inputs from callers who cannot edit job scripts.

Pass string inputs through job variables with expand: false in both templates. Copy these values into SETUP_VP_* at runtime to keep input precedence. Multiline values, quotes, and dollar signs remain literal data.

@fengmk2
fengmk2 requested a review from naokihaba October 8, 2026 16:16
@fengmk2 fengmk2 self-assigned this Oct 8, 2026

@naokihaba naokihaba left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry about the oversight, and thanks for fixing that. 🙇‍♂️

@fengmk2

fengmk2 commented Oct 10, 2026

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T14:54:09.908692Z 7bc3ddd Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 7bc3ddde4a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@fengmk2
fengmk2 merged commit 16e60ef into main Oct 10, 2026
159 of 160 checks passed
@fengmk2
fengmk2 deleted the fix/gitlab-input-shell-injection branch October 10, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants