How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories
ID: 1f750bdd-eef9-5e7d-8cc8-b7454764dafb
STIX ID: report--1f750bdd-eef9-5e7d-8cc8-b7454764dafb
Feed Name: Kudelski Security
## Executive summary This write-up describes a critical vulnerability in CodeRabbit where RuboCop configuration files in user repositories could be used to execute arbitrary Ruby code during automated analysis, resulting in RCE on production servers; attackers achieved environment variable exfiltration (including API keys, DB credentials, and the CodeRabbit GitHub App private key) and demonstrated how the private key could be used to enumerate installations and generate short-lived access tokens to access or modify potentially up to 1M repositories. The authors responsibly disclosed the issue, CodeRabbit remediated the flaw and rotated secrets, and the report recommends isolating external tools and minimizing environment exposure to prevent similar exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
