Skip to content
Threat Feed

Tag

Ci-Cd

12 briefs RSS
medium advisory

Unauthorized Command Execution via Self-Hosted GitHub Actions Runners

Adversaries gaining unauthorized workflow trigger access can abuse GitHub Actions runners to execute arbitrary system commands, potentially leading to credential harvesting, reconnaissance, and CI/CD supply chain compromise.

GitHub Actions +1 execution supply-chain ci-cd lotl
1r 1t updated
high advisory

Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action

A supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.

quay-builder-qemu supply-chain ci-cd vulnerability
2t 1c
medium advisory

Octopus Deploy File Path Manipulation and Potential RCE

A vulnerability in Octopus Deploy allows remote attackers to perform unauthorized file manipulation and potentially execute arbitrary code due to improper path validation.

Octopus Deploy vulnerability rce ci-cd
1t 1c
high advisory

OS Command Injection in @argos-ci/core via CI Branch Names

The @argos-ci/core package is vulnerable to OS command injection when processing unvalidated branch or reference names in environments where hasRemoteContentAccess is disabled, allowing arbitrary code execution on CI runners.

@argos-ci/core +1 ci-cd command-injection supply-chain
1t
high advisory

Remote Code Execution in Spinnaker rosco-manifests via Kustomize

The Spinnaker rosco-manifests package is vulnerable to remote code execution (RCE) via improper YAML processing during Kustomize bake operations, allowing attackers to execute arbitrary code on rosco pods.

rosco-manifests vulnerability rce ci-cd spinnaker
1t 1c
critical advisory

Wazuh GitHub Actions Shell Injection Vulnerability

A shell injection vulnerability in Wazuh workflows allows unauthenticated attackers to execute arbitrary commands and exfiltrate secrets via malicious pull requests containing crafted VERSION.json files.

Wazuh supply-chain ci-cd code-injection
3t 1c
critical advisory

Gitea Actions Fork Pull Request Approval Gate Bypass

A vulnerability in Gitea Actions (versions v1.20.0 and later) allows an unprivileged attacker to permanently bypass the fork pull request approval gate for a repository after a single, initial workflow approval, enabling arbitrary shell command execution on the Gitea Actions runner without further maintainer interaction, leading to source code disclosure and potential system compromise.

PoC Gitea +1 logic-bug ci-cd code-execution privilege-escalation gitea-actions
4t 1c 1i updated
critical advisory

Nuclio Java Runtime Vulnerability Leads to Build-Time Remote Code Execution

Nuclio's Java runtime dashboard API, by default configured with NOP authentication, is vulnerable to remote code execution (CWE-94) where attackers can inject arbitrary Groovy code into the unsanitized `runtimeAttributes.repositories` field, which is directly written into the `build.gradle` file, allowing the injected code to execute during the Gradle configuration phase as root within the build container.

Nuclio <= 1.15.27 code-injection rce template-injection kubernetes ci-cd groovy
1r 5t 1i
critical advisory

AsyncAPI npm Supply Chain Compromise via GitHub Actions

Threat actors compromised AsyncAPI npm packages by exploiting a misconfigured GitHub Actions workflow, stealing a privileged bot token, and injecting obfuscated Miasma malware into multiple packages, which then executed at module-load time to establish persistence and command and control, bypassing standard npm installation mitigations.

@asyncapi/generator@3.3.1 +4 supply-chain npm github-actions malware javascript nodejs ci-cd
2r 9t 3i
low advisory

Trivy Unbounded Read Leads to Denial of Service via Helm Chart Tar Bomb

Trivy versions prior to 0.71.0 are vulnerable to CVE-2026-54448, a denial-of-service attack where a crafted Helm chart archive (.tgz) can cause unbounded memory consumption, leading to the OS OOM killer terminating the Trivy process and other services on the host or CI runner.

Trivy supply-chain vulnerability denial-of-service ci-cd
1t 1c
high advisory

Woodpecker CI gRPC Vulnerability Allows Cross-Tenant Agent Impersonation (CVE-2026-50141)

A high-severity vulnerability (CVE-2026-50141) in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` into gRPC metadata, leading to potential privilege escalation and unauthorized access within CI/CD pipelines.

Woodpecker CI v3 privilege-escalation vulnerability grpc ci-cd
1t 1c
critical advisory

GitHub Actions Workflow Command Injection via Issue Comments

A GitHub Actions workflow uses untrusted user input from `issue_comment.body` directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner.

GitHub Actions +1 github-actions command-injection ci-cd
2r 1t