Web Hack List

Collected research

Artifact Poisoning Vulnerability Discovered in GitHub Actions

Describes cross-workflow artifact poisoning in GitHub Actions. Artifact APIs and download actions failed to distinguish outputs created by forks, so a pull request could upload a same-named malicious artifact that a privileged Rust workflow later downloaded and executed.

Record

Researcher
Noam Dotan
Published by
Legit Security
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Noam Dotan, first published at the original source. Preserved copies are kept so the citation survives its host.