Skip to content

[security-fix] Security Fix: Unsafe Quoting in Network Hook Generation (Alert #9) - #1521

Merged
pelikhan merged 5 commits into
mainfrom
fix/alert-9-unsafe-quoting-58a86ada7a3d8092
Oct 11, 2025
Merged

pelikhan merged 5 commits into
mainfrom
fix/alert-9-unsafe-quoting-58a86ada7a3d8092

Add changeset for security fix: unsafe quoting in network hooks

0934789
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Oct 11, 2025 in 3s

1 new alert including 1 critical severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 critical

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 112 in pkg/workflow/engine_network_hooks.go

See this annotation in the file changed.

Code scanning / CodeQL

Potentially unsafe quoting Critical

If this
JSON value
contains a double quote, it could break out of the enclosing quotes.
If this
JSON value
contains a single quote, it could break out of the enclosing quotes.
If this
JSON value
contains a double quote, it could break out of the enclosing quotes.
If this
JSON value
contains a single quote, it could break out of the enclosing quotes.