Описание
Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.
Ссылки
- Patch
- Third Party Advisory
- Exploit
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.6.1 (исключая)
cpe:2.3:a:skim-rs:skim:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 21%
0.00281
Низкий
7.4 High
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 7.4
debian
4 месяца назад
Skim is a fuzzy finder designed to through files, lines, and commands. ...
EPSS
Процентиль: 21%
0.00281
Низкий
7.4 High
CVSS3
Дефекты
CWE-94