< Back to all clusters
[TECHNOLOGY] · United States, Germany · 3 sources

GitHub Actions flaws expose 300+ repositories to supply‑chain attacks

Security researchers have uncovered two serious issues in GitHub Actions pipelines that could enable large‑scale supply‑chain compromises.

Tenable reported a critical vulnerability (CVSSv4 9.3) in Microsoft’s public GitHub repository “Windows-driver-samples”. The flaw allows an attacker to create a GitHub issue, inject malicious Python code into the workflow, trigger remote code execution and read the repository’s GITHUB_TOKEN and other secrets. Tenable warns that CI/CD pipelines are now a core part of the software‑supply‑chain attack surface.

Separately, Novee Security identified a class of vulnerabilities termed “Cordyceps” in GitHub Actions YAML configurations. The bugs let any unauthenticated user with a free GitHub account manipulate pull‑request events to execute code, steal automation tokens and gain write access to over 300 high‑profile repositories, including Microsoft Azure Sentinel, Google’s AI Agent Development Kit, Cloudflare Workers SDK, Apache Doris and the Python Software Foundation’s Black formatter. The researchers attribute rapid propagation of the flaw to AI‑driven code generation tools that copy insecure templates.

Both incidents highlight how misconfigurations in CI/CD workflows can give attackers a powerful foothold in the software supply chain, prompting affected organisations to roll out patches and tighten pipeline permissions.

Sources

about 1 month ago
25 Jahre alte cURL-Lücke geschlossen [www.all-about-security.de]
about 1 month ago
about 1 month ago