Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests
Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.
- from
- CI/CD Attacks
- added
- 2026-10-10
- likes
- 0
similar
-
Keeping your GitHub Actions and workflows secure Part 2: Untrusted input securitylab.github.com
GitHub Actions command injection.
-
Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com
GitHub Actions workflow_run PE.
-
Unpinnable Actions: How Malicious Code Can Sneak into Your GitHub Actions Workflows paloaltonetworks.com
GitHub Actions, even when pinned to a commit SHA, can still pull in malicious code via mutable dependencies like Docker images, unlocked packages, or external scripts.
-
-
Bypassing required reviews using GitHub Actions medium.com
GitHub Actions can bypass required reviews, allowing malicious code pushes to protected branches.
-
How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com
Extracting all repository and organization secrets in GitHub Actions.
CI/CD Attacks › Techniques > Initial Code Execution: “Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.”