Collected research
Artifact Poisoning Vulnerability Discovered in GitHub Actions
Describes cross-workflow artifact poisoning in GitHub Actions. Artifact APIs and download actions failed to distinguish outputs created by forks, so a pull request could upload a same-named malicious artifact that a privileged Rust workflow later downloaded and executed.
Record
- Researcher
- Noam Dotan
- Published by
- Legit Security
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Noam Dotan, first published at the original source. Preserved copies are kept so the citation survives its host.