{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/act/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76847"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["act"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["nektos"],"content_html":"\u003cp\u003eThe 'act' tool, used for running GitHub Actions locally, exposes a critical security vulnerability (CVE-2026-76847) in its HTTP Artifacts V4 backend implementation. Introduced to support actions/upload-artifact@v4 and actions/download-artifact@v4, this backend fails to validate the \u003ccode\u003eworkflow_run_backend_id\u003c/code\u003e parameter against the requesting task, essentially disabling access control. Furthermore, the backend uses a static, hardcoded four-byte HMAC key (0xba 0xdb 0xee 0xf0) for signing artifact URLs. The flawed construction of these signatures, combined with the fact that the artifact server defaults to listening on all network interfaces rather than loopback, allows any reachable attacker to read, overwrite, or delete build artifacts. This vulnerability enables the theft of sensitive data such as hardcoded secrets, API keys, or deployment credentials, and allows attackers to inject malicious files into the CI/CD pipeline of a target machine.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete compromise of CI/CD build outputs handled by the 'act' tool. Unauthorized actors can exfiltrate sensitive environment variables, deployment tokens, and build artifacts, or manipulate files to facilitate supply-chain attacks on build processes. Given the hardcoded key and lack of network binding restrictions, any attacker with network visibility to the host running 'act' can perform these operations without credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'act' tool to the latest patched version immediately to resolve CVE-2026-76847.\u003c/li\u003e\n\u003cli\u003eInspect existing network configurations for hosts running 'act'; ensure that artifact server ports are not exposed to untrusted networks.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress and ingress filtering to restrict access to the 'act' artifact server port (typically configured via \u003ccode\u003e--artifact-server-addr\u003c/code\u003e) to localhost only.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD logs for unauthorized access to artifact endpoints or unexpected artifact modification events if the tool was previously deployed in a shared or non-isolated environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T16:02:45Z","date_published":"2026-08-24T16:02:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-act-artifacts-v4-auth-bypass/","summary":"The 'act' tool's HTTP Artifacts V4 backend suffers from an authentication bypass and hardcoded HMAC key vulnerability (CVE-2026-76847), allowing unauthorized network actors to access, modify, or delete artifacts and exfiltrate secrets.","title":"Authentication Bypass and Artifact Manipulation in 'act' HTTP Artifacts V4 Backend","url":"https://feed.craftedsignal.io/briefs/2026-08-act-artifacts-v4-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Act","version":"https://jsonfeed.org/version/1.1"}