logo

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories

ID: 1f750bdd-eef9-5e7d-8cc8-b7454764dafb

STIX ID: report--1f750bdd-eef9-5e7d-8cc8-b7454764dafb

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2025-08-19

Date Updated: 2026-07-22

...
...

## Executive summary This write-up describes a critical vulnerability in CodeRabbit where RuboCop configuration files in user repositories could be used to execute arbitrary Ruby code during automated analysis, resulting in RCE on production servers; attackers achieved environment variable exfiltration (including API keys, DB credentials, and the CodeRabbit GitHub App private key) and demonstrated how the private key could be used to enumerate installations and generate short-lived access tokens to access or modify potentially up to 1M repositories. The authors responsibly disclosed the issue, CodeRabbit remediated the flaw and rotated secrets, and the report recommends isolating external tools and minimizing environment exposure to prevent similar exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.