Web Hack List

Collected research

GitHub Actions exploitation: untrusted input

Three GitHub Actions misconfigurations, untrusted expression interpolation into run scripts, unvalidated artifacts consumed by follow-up workflows, and explicit checkouts of fork code under a privileged trigger, let an outside contributor execute code in a privileged runner, steal repository secrets and push to the repository.

Record

Researcher
@Synacktiv
Published by
Synacktiv
Topic
Supply

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @Synacktiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .