{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cal.com-calcom/cal.diy-repository/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2024-58354"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cal.com (calcom/cal.diy repository)","GitHub Actions"],"_cs_severities":["critical"],"_cs_tags":["github-actions","repository-takeover","vulnerability","cloud-security"],"_cs_type":"advisory","_cs_vendors":["cal.com","GitHub"],"content_html":"\u003cp\u003eA critical repository takeover vulnerability, identified as CVE-2024-58354, affects the cal.com (specifically the \u003ccode\u003ecalcom\u003c/code\u003e repository, later renamed \u003ccode\u003ecal.diy\u003c/code\u003e) project's GitHub Actions workflows. Attackers can exploit this by submitting a specially crafted pull request. The vulnerable \u003ccode\u003epr.yml\u003c/code\u003e workflow, triggered by \u003ccode\u003epull_request_target\u003c/code\u003e events, inadvertently grants its default write permissions (via the GITHUB_TOKEN) to a downstream workflow, \u003ccode\u003echeck-types.yml\u003c/code\u003e. This \u003ccode\u003echeck-types.yml\u003c/code\u003e then utilizes a \u0026quot;dangerous\u0026quot; checkout action to retrieve the attacker's submitted pull request code and subsequently executes it through \u003ccode\u003eyarn install\u003c/code\u003e and \u003ccode\u003epackage.json\u003c/code\u003e scripts. This execution takes place with the repository's write-scoped token, enabling the attacker to perform arbitrary actions such as pushing commits, merging or mutating pull requests, adding or deleting comments, and deleting or force-pushing branches, effectively leading to a full compromise of the main branch and its associated codebase. No patched version is currently available for this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious pull request containing arbitrary commands within \u003ccode\u003epackage.json\u003c/code\u003e scripts.\u003c/li\u003e\n\u003cli\u003eThe attacker submits this pull request to the vulnerable cal.com repository.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003epr.yml\u003c/code\u003e GitHub Actions workflow is triggered by the \u003ccode\u003epull_request_target\u003c/code\u003e event.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003epr.yml\u003c/code\u003e workflow, by design, passes its default repository write permissions (via \u003ccode\u003eGITHUB_TOKEN\u003c/code\u003e) to the \u003ccode\u003echeck-types.yml\u003c/code\u003e workflow.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003echeck-types.yml\u003c/code\u003e workflow uses a \u0026quot;dangerous\u0026quot; checkout action to fetch the attacker's malicious pull request code.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003echeck-types.yml\u003c/code\u003e executes \u003ccode\u003eyarn install\u003c/code\u003e and subsequent \u003ccode\u003epackage.json\u003c/code\u003e scripts from the attacker-controlled code.\u003c/li\u003e\n\u003cli\u003eThe attacker's arbitrary commands are executed with the repository's write-scoped \u003ccode\u003eGITHUB_TOKEN\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker gains full control over the repository, capable of pushing commits, merging pull requests, and manipulating branches, leading to a complete repository compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2024-58354 results in a complete repository takeover for the affected cal.com GitHub repository. Attackers can gain the ability to inject malicious code, tamper with the software supply chain, delete or alter source code, and potentially compromise the integrity of releases. This could lead to backdoored software distributed to users, data exfiltration from the repository, or disruption of development workflows. As the main branch is affected and no patch is available, the risk remains high for organizations using or contributing to the cal.com project.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview all GitHub Actions workflows, particularly \u003ccode\u003epr.yml\u003c/code\u003e and \u003ccode\u003echeck-types.yml\u003c/code\u003e, for the use of \u003ccode\u003epull_request_target\u003c/code\u003e in conjunction with write permissions and dangerous checkout actions as described in CVE-2024-58354.\u003c/li\u003e\n\u003cli\u003eDisable or refactor GitHub Actions workflows that use \u003ccode\u003epull_request_target\u003c/code\u003e with default write permissions and perform untrusted code execution to mitigate CVE-2024-58354.\u003c/li\u003e\n\u003cli\u003eImplement \u0026quot;least privilege\u0026quot; for GitHub Actions workflows, explicitly limiting permissions for GITHUB_TOKEN rather than relying on default write permissions.\u003c/li\u003e\n\u003cli\u003eAudit existing GitHub Actions workflow logs for any suspicious activity or unexpected command execution that could indicate prior exploitation of CVE-2024-58354.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T22:20:33Z","date_published":"2026-07-23T22:20:33Z","id":"https://feed.craftedsignal.io/briefs/2026-07-calcom-repo-takeover/","summary":"A critical repository takeover vulnerability (CVE-2024-58354) exists in the cal.com (calcom/cal.diy) GitHub Actions workflows, allowing an attacker to submit a malicious pull request that executes arbitrary commands with write permissions to the repository, leading to full compromise.","title":"Repository Takeover Vulnerability in cal.com GitHub Actions (CVE-2024-58354)","url":"https://feed.craftedsignal.io/briefs/2026-07-calcom-repo-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Cal.com (Calcom/Cal.diy Repository)","version":"https://jsonfeed.org/version/1.1"}