Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process…
Leaking secrets from vulnerable GitHub Actions workflows is possible via several methods: reading files/environment variables, intercepting communication, and dumping runner memory.
- from
- CI/CD Attacks
- added
- 2026-10-10
- likes
- 0
similar
-
How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com
Extracting all repository and organization secrets in GitHub Actions.
-
Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com
GitHub Actions workflow_run PE.
-
-
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io
Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.
-
One Supply Chain Attack to Rule Them All – Poisoning GitHub's Runner Images adnanthekhan.com
A critical vulnerability in GitHub Actions, involving a misconfigured self-hosted runner in the actions/runner-images repository, allowed potential compromise of all GitHub and Azure hosted runner images.
-
Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests securitylab.github.com
Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.
CI/CD Attacks › Techniques > Post Exploitation: “Leaking secrets from vulnerable GitHub Actions workflows is possible via several methods: reading files/environment variables, intercepting communication, and dumping runner memory.”