dedupe icon indicating copy to clipboard operation
dedupe copied to clipboard

Critical Secrets exfiltration vulnerability

Open darryk10 opened this issue 6 months ago • 1 comments

Hi, We found a critical vulnerability in one of the CI workflows in this repo. The repository remains vulnerable, allowing an attacker to exfiltrate secrets and a highly privileged GITHUB_TOKEN, potentially compromising the overall repository content. This would impact all the repo users We are happy to coordinate for full disclosure and receive proper CVE via Github Security Advisory (GHSA).

darryk10 avatar Jul 11 '25 07:07 darryk10

thank you. i have enabled GHSA on this repo. please report the issue you have found.

fgregg avatar Jul 28 '25 19:07 fgregg