logo

Node.js repository CI/CD vulnerable to RCE (Research)

ID: 30d71009-ffb1-559c-bccf-8fb38c468690

STIX ID: report--30d71009-ffb1-559c-bccf-8fb38c468690

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2025-04-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A researcher discovered a critical vulnerability in the Node.js CI/CD workflow that allowed an attacker to forge Git commit timestamps to smuggle unreviewed malicious commits into Jenkins pipelines; the payload modified build scripts to install a rogue GitHub Actions runner, enabling persistent remote code execution on over a dozen Jenkins agents and exposing a substantial supply-chain and credential-exfiltration risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.