OZI-Project/ozi-publish Code Injection vulnerability
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          May 10, 2025 
          in
          
            OZI-Project/publish
          
          •
          Updated May 12, 2025 
      
  
Package
Affected versions
>= 1.13.2, < 1.13.6
  Patched versions
1.13.6
  Description
        Published by the National Vulnerability Database
      May 12, 2025 
    
  
        Published to the GitHub Advisory Database
      May 12, 2025 
    
  
        Reviewed
      May 12, 2025 
    
  
        Last updated
      May 12, 2025 
    
  
Impact
Potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code.
Patches
This is patched in 1.13.6
Workarounds
Downgrade to <1.13.2
References
References