logo

Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositories

ID: 2acd2dad-14bc-5d8b-8f49-6c5d97b5c5a5

STIX ID: report--2acd2dad-14bc-5d8b-8f49-6c5d97b5c5a5

Feed Name: Sysdig Blog

Threat Score
75/100

Date Published: 2025-06-17

Date Updated: 2026-05-01

...
...

This Sysdig Threat Research Team report demonstrates how insecure GitHub Actions workflows—particularly those using the pull_request_target trigger and checking out untrusted fork code—can be trivially exploited to run attacker-controlled code (via pip/install hooks or requirements) to exfiltrate secrets and high-privilege GITHUB_TOKENs; the team successfully exploited and reported issues in multiple well-known repositories (Spotipy — CVE-2025-47928, MITRE CAR, and Splunk) and provides mitigation guidance such as splitting workflows, restricting token permissions, and using runtime detection (Falco Actions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.