dogear

enter for all results · esc to close

PR sneaking

github.comtool

Methods of sneaking malicious code into GitHub pull requests.

from
CI/CD Attacks
added
2026-10-10
likes
0

similar

  1. Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests securitylab.github.com

    Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.

  2. Bypassing required reviews using GitHub Actions medium.com

    GitHub Actions can bypass required reviews, allowing malicious code pushes to protected branches.

  3. Unpinnable Actions: How Malicious Code Can Sneak into Your GitHub Actions Workflows paloaltonetworks.com

    GitHub Actions, even when pinned to a commit SHA, can still pull in malicious code via mutable dependencies like Docker images, unlocked packages, or external scripts.

  4. Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process… karimrahal.com

    Leaking secrets from vulnerable GitHub Actions workflows is possible via several methods: reading files/environment variables, intercepting communication, and dumping runner memory.

  5. Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com

    GitHub Actions workflow_run PE.

  6. Hacking GitHub AWS integrations again dagrz.com

    Attacking misconfigured pipelines that use OIDC.

CI/CD Attacks › Techniques > Defense Evasion: “Methods of sneaking malicious code into GitHub pull requests.”