Impact
Conflibot warns of merge conflicts between open pull requests, but before version 1.2.1 its source builds git checkout, git merge, and git format‑patch commands by inserting the pull request’s head.ref value directly into the shell command string. In the documented pull_request_target configuration, an attacker can open a pull request—also from a fork—whose branch name contains shell metacharacters; the workflow then interprets these characters as additional shell commands. When these commands run on the GitHub Actions runner, they execute with the repository’s base‑repository secrets and a write‑scoped GITHUB_TOKEN, allowing arbitrary command execution, secret theft, unauthorized pushes, and other token abuse. The flaw is a classic command injection (CWE‑78), and it can be triggered with no interaction from the repository maintainers. The fix in v1.2.1 and v2.0.0 replaces string interpolation with execFile or spawn argument arrays, and the v2 line also switches to numeric pull‑request references rather than branch names.
Affected Systems
The vulnerability affects Conflibot deployments provided by wktk. Versions prior to v1.2.1 and v2.0.0 are affected; upgrading to v1.2.1 or any later release eliminates the trait of interpolating branch names into shell commands.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, and the EPSS score of < 1% suggests a low probability of exploitation, though the zero‑effort and high‑value target of this vulnerability make it a meaningful risk. The flaw is exploitable in public pull_request_target workflows, a common GitHub Actions pattern. The attacker only needs to create a pull request from a fork with a specially crafted branch name. Once the workflow runs, the injected commands execute with the runner’s base‑repository secrets and a write‑scoped GITHUB_TOKEN, providing a foothold for full compromise. The flaw is not listed in the CISA KEV catalog but the potential impact is high enough that rapid remediation is warranted.
OpenCVE Enrichment
Github GHSA