Collected research
Stealing arbitrary GitHub Actions secrets
A validation gap let attackers edit a pull request's base ref from a branch to an attacker-controlled commit shared through a fork. GitHub Actions then treated that commit as trusted for pull_request_target, ran a malicious workflow with repository secrets and a write-capable GITHUB_TOKEN, enabling credential theft and potential package-supply-chain compromise.
Record
- Published by
- Teddy Katz’s Blog
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Teddy Katz’s Blog, first published at the original source. Preserved copies are kept so the citation survives its host.