dogear

enter for all results · esc to close

Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests

securitylab.github.comsite

Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.

from
CI/CD Attacks
added
2026-10-10
likes
0

similar

  1. Keeping your GitHub Actions and workflows secure Part 2: Untrusted input securitylab.github.com

    GitHub Actions command injection.

  2. Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com

    GitHub Actions workflow_run PE.

  3. Unpinnable Actions: How Malicious Code Can Sneak into Your GitHub Actions Workflows paloaltonetworks.com

    GitHub Actions, even when pinned to a commit SHA, can still pull in malicious code via mutable dependencies like Docker images, unlocked packages, or external scripts.

  4. PR sneaking github.com

    Methods of sneaking malicious code into GitHub pull requests.

  5. Bypassing required reviews using GitHub Actions medium.com

    GitHub Actions can bypass required reviews, allowing malicious code pushes to protected branches.

  6. How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com

    Extracting all repository and organization secrets in GitHub Actions.

CI/CD Attacks › Techniques > Initial Code Execution: “Combining pull_request_target workflow trigger with an explicit checkout of an untrusted PR may lead to repository compromise.”