Web Hack List

Collected research

Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory

Turns a command injection in a GitHub Actions workflow into full secret disclosure: reading the expanded .sh files the runner writes under _temp, dumping the environment of Node.js action processes, and most reliably using sudo and gcore to dump Runner.Listener memory, which yields every workflow secret plus the read-write GITHUB_TOKEN even when none are referenced.

Record

Published by
karimrahal.com
Topic
Supply

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of karimrahal.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .