logo

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

ID: 699521b2-7816-5bcc-bd4d-6aef5dafa274

STIX ID: report--699521b2-7816-5bcc-bd4d-6aef5dafa274

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-01-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers found misconfigurations in TensorFlow's CI/CD (self-hosted GitHub Actions runners and overly permissive GITHUB_TOKEN/AWS_PYPI_ACCOUNT_TOKEN usage) that could be abused via malicious pull requests to gain remote code execution on runners, steal tokens, upload malicious GitHub releases, or publish poisoned PyPI packages; maintainers remediated the issues by requiring approval for forked PR workflows and restricting token permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.