Potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code.
This is patched in 1.13.6
Downgrade to <1.13.2
{
"nvd_published_at": "2025-05-12T11:15:51Z",
"cwe_ids": [
"CWE-1116",
"CWE-94",
"CWE-95"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-05-12T19:58:07Z"
}