Description
Setting ACTIONS_ALLOW_UNSECURE_COMMANDS to true re-enables the deprecated set-env and add-path commands. If untrusted input reaches a step’s standard output, an attacker may manipulate environment variables or PATH.
Potential impact
- Unintended environment variables or executable search paths may affect later steps.
- Steps using the altered environment may execute an attacker’s chosen command; the impact depends on the job’s permissions and access to secrets.
Remediation
Remove ACTIONS_ALLOW_UNSECURE_COMMANDS: true and replace set-env and add-path with the GITHUB_ENV and GITHUB_PATH environment files. Do not interpolate untrusted values directly into scripts, and restrict workflow permissions and access to secrets.
Examples
Do not use the before example as written: it allows insecure commands and inserts GitHub context directly into Python code. The after example writes a fixed value to an environment file without that flag. Changing the event alone does not resolve every risk from external input.
Before
name: Vulnerable workflow
on:
pull_request_target
env:
ACTIONS_ALLOW_UNSECURE_COMMANDS: true
ENVIRONMENT_NAME: prod
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- run: |
print("""${{ toJSON(github) }}""")
shell: python
After
name: Safe workflow
on:
pull_request:
types: [opened, synchronize, edited, reopened]
branches:
- master
jobs:
review-comment:
runs-on: ubuntu-latest
steps:
- name: Set review flag
run: echo "REVIEW_STARTED=true" >> "$GITHUB_ENV"
Values written to GITHUB_ENV are available to later steps in the same job. Follow the documented syntax when writing untrusted multiline values to environment files as well.