Web Hack List

Collected research

Stealing arbitrary GitHub Actions secrets

A validation gap let attackers edit a pull request's base ref from a branch to an attacker-controlled commit shared through a fork. GitHub Actions then treated that commit as trusted for pull_request_target, ran a malicious workflow with repository secrets and a write-capable GITHUB_TOKEN, enabling credential theft and potential package-supply-chain compromise.

Record

Published by
Teddy Katz’s Blog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Teddy Katz’s Blog, first published at the original source. Preserved copies are kept so the citation survives its host.