Y
Hacker News
new
|
ask
|
show
|
jobs
by
raggi
1420 days ago
This code does more than leak environments. The go code pulls down arbitrary text and passes it to sh -c, example:
https://github.com/zerops-io/zcli/commit/0396ee57bc0e5e0b123...