dogear

enter for all results · esc to close

Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline

legitsecurity.comsite

GitHub Actions workflow_run PE.

from
CI/CD Attacks
added
2026-10-10
likes
0

similar

  1. Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests securitylab.github.com

    Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.

  2. Keeping your GitHub Actions and workflows secure Part 2: Untrusted input securitylab.github.com

    GitHub Actions command injection.

  3. How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com

    Extracting all repository and organization secrets in GitHub Actions.

  4. The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io

    Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.

  5. Bypassing required reviews using GitHub Actions medium.com

    GitHub Actions can bypass required reviews, allowing malicious code pushes to protected branches.

  6. Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process… karimrahal.com

    Leaking secrets from vulnerable GitHub Actions workflows is possible via several methods: reading files/environment variables, intercepting communication, and dumping runner memory.

CI/CD Attacks › Techniques > Initial Code Execution: “GitHub Actions workflow_run PE.”