Impact
An OS command injection flaw exists in Argos JavaScript’s core package that allows an attacker to manipulate CI branch or ref values supplied via GITHUB_HEAD_REF or ARGOS_BRANCH through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. These values are interpolated into execSync() command strings used by gitFetch() and gitMergeBase() and executed via /bin/sh -c, so shell metacharacters in a pull‑request branch name can trigger arbitrary commands with the Argos upload process privileges on the CI runner. Successful exploitation compromise the entire runner environment. The vulnerability exemplifies CWE‑78, where untrusted input is used to build operating‑system commands without proper sanitization.
Affected Systems
The issue impacts the Argos SDK for JavaScript (repo argos-ci/argos-javascript) when using the core package at versions earlier than 6.2.1. Users running Argos core versions 6.0.x through 6.2.0 are susceptible, while version 6.2.1 and later contain the fix. The vulnerability arises when CI environments set the environment variables GITHUB_HEAD_REF or ARGOS_BRANCH to attacker‐controlled values and the flag hasRemoteContentAccess is false, causing the branch name to flow into command strings.
Risk and Exploitability
The CVSS score the High severity category. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the C likely attack vector involves an attacker submitting a pull request with a specially crafted branch name that contains shell metacharacters. If the CI job is executed with the Argos upload process, the payload will run with the job runner’s privileges, potentially leaking secrets, corrupting build artifacts, or compromising the entire runner environment.
OpenCVE Enrichment
Github GHSA