Description
Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
References
github.com/...nchair/security/advisories/GHSA-9prc-pp2c-3427
github.com/...nchair/security/advisories/GHSA-9prc-pp2c-3427
github.com/...ommit/fcba413f55dd47f8a3921445252849126c6266b2