CVE-2023-26493
Summary
| CVE | CVE-2023-26493 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-27 22:15:00 UTC |
| Updated | 2023-04-03 18:26:00 UTC |
| Description | Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `web-interface-check.yml` was subject to command injection. The `web-interface-check.yml` was triggered when a pull request was opened or updated and contained the user controllable field `(${{ github.head_ref }} – the name of the fork’s branch)`. This would allow an attacker to take over the GitHub Runner and run custom commands (potentially stealing secrets such as GITHUB_TOKEN) and altering the repository. The workflow has since been removed for the repository. There are no actions required of users. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cocos | Cocos-engine | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| remove interface check workflow (#14281) · cocos/cocos-engine@6d06aef · GitHub | MISC | github.com | |
| GHSL-2023-027: Command Injection in Cocos - CVE-2023-26493 | GitHub Security Lab | MISC | securitylab.github.com | |
| cocos-engine/web-interface-check.yml at 2362df28a4b3016dbda804899041279701929728 · cocos/cocos-engine · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.