← LibraryTechnique entry
CI-WORKFLOW-INJECTExecution
Workflow Command Injection
User input interpolated into a run: step (e.g. github.event.issue.title) — RCE on the runner via shell metachars.
§ Where this technique fits
CI-WORKFLOW-INJECT is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 4 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Secret Echo to Build Logseen 1×CI-SECRET-IN-LOG · Credential Access