This github trick could allow the attackers to steal secrets of the main projects, and no one is paying attention




  • Sysdig exposed how a trusted github feature can silently control the attackers
  • Pull_request_target is not just risky, it is a weapon loaded in the wrong hands
  • Even top -level safety projects such as Miter’s can fall into simple erroneous configurations of github workflow

Experts have revealed several critical vulnerabilities in Github Actions’s workflows that could represent serious risks for some important open source projects.

Recent research conducted by the Sysdig threat research team (TRT) has exposed how erroneous configurations, particularly that they involve the trigger Pull_request_target, could allow the attackers to seize control over active repositories or extract sensitive credentials.

Leave a Comment

Your email address will not be published. Required fields are marked *