Critical severity9.2NVD Advisory· Published Dec 28, 2022· Updated Jun 17, 2026
CVE-2022-46179
CVE-2022-46179
Description
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is patched in the latest commit (c658b4f3e57258acf5f6207a90c2f2169698ae22) by requiring the var to be set to true, causing a test script to run instead of being able to login. A potential workaround is to check for the GITHUB_ACTIONS environment variable and set it to "" (no quotes) to null the variable and force credential checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=0.1.0+ 1 more
- (no CPE)range: <=0.1.0
- (no CPE)range: <= 0.1.0
Patches
Vulnerability mechanics
References
2- github.com/LiuWoodsCode/LiuOS/commit/c658b4f3e57258acf5f6207a90c2f2169698ae22nvdPatchThird Party Advisory
- github.com/LiuWoodsCode/LiuOS/security/advisories/GHSA-f9x3-mj2r-cqmfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.