Collected research
GitHub Actions exploitation: untrusted input
Three GitHub Actions misconfigurations, untrusted expression interpolation into run scripts, unvalidated artifacts consumed by follow-up workflows, and explicit checkouts of fork code under a privileged trigger, let an outside contributor execute code in a privileged runner, steal repository secrets and push to the repository.
Record
- Researcher
- @Synacktiv
- Published by
- Synacktiv
- Topic
- Supply
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @Synacktiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .