logo

Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositories

ID: 74896a60-9c26-5887-98cd-c6740df20c18

STIX ID: report--74896a60-9c26-5887-98cd-c6740df20c18

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2025-06-17

Date Updated: 2026-05-01

...
...

The Sysdig Threat Research Team discovered that many open-source GitHub Actions workflows using the pull_request_target trigger are misconfigured, enabling attackers to check out untrusted code from forks, run malicious install steps (e.g., via pip/setup.py), exfiltrate secrets (including high-privilege GITHUB_TOKENs) and take over repositories; the report details confirmed incidents against Spotipy (CVE-2025-47928), MITRE CAR, and Splunk, and provides mitigation guidance such as splitting workflows, restricting GITHUB_TOKEN permissions, label gating, and using runtime detection with Falco Actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.