GitHub has finally patched a serious vulnerability reported to it by security Google's. The researchers had updated GitHub three months ago.

The vulnerability affected GitHub's Actions feature . According to Google researcher Felix Wilhelm, the vulnerability made the Actions tool vulnerable to "injection attacks" .
Google had said that this was a very serious vulnerability, however GitHub did not immediately respond as it claimed that it was a “moderate security vulnerability”.
The Google Project Zero team usually publicly discloses bugs they find 90 days after they are reported to the appropriate authority. The 90-day period passed, and GitHub still hadn't fixed the vulnerability. researchers gave them another 14 days, but still nothing happened. So they decided to disclose the vulnerability (in early November).
A day before the planned disclosure (after an extension had been granted), GitHub told Google that it would not disable the vulnerable Actions workflow commands until November 2nd and asked for an additional 48 hours. However, these extra hours would be to inform customers about a future resolution to the issue, not to fix the vulnerability.

Google's research team decided to disclose the vulnerability and not give more time, since 104 days had already passed since the initial report on GitHub.
GitHub finally patched the vulnerability last week, disabling the old Actions runner commands, “set-env” and “add-path”, as researcher Wilhelm had suggested.
The fix was released on November 16 , two weeks after Google disclosed the vulnerability
As Wilhelm said, Action was vulnerable to injection attacks, due to the vulnerability that could ultimately lead to malicious code execution.
Now that GitHub has disabled the two vulnerable commands, Wilhelm has updated his report and confirmed that the issue has been resolved.
Source: ZDNet
