vulns.co
/
GKData.io MCP

SCSoftware supply-chain security · 2 min read

Angular automation trust and cache isolation weakness

A Google-rewarded report connected an adjacent CI misconfiguration with insufficient separation of automation trust, creating a potential Angular supply-chain impact.

Read the primary source SCSoftware supply-chain securityReviewed 2026-10-03

Root cause

Untrusted workflow input and shared build state crossed trust boundaries; bot-specific approval assumptions increased the potential consequence.

Demonstrated impact

The researcher demonstrated credential exposure and modeled the remaining path to repository control without executing the final supply-chain modification. Google classified the report as a flagship supply-chain compromise.

Lessons for review

  • Separate caches and artifacts according to trust level.
  • Apply consistent review invalidation and least-privilege rules to automated identities.
  • Record which impacts were directly demonstrated versus established through design evidence.

Award and evidence

USD 31,337Bug Bounty · Researcher Reported With Vendor Quote

A Google award email is quoted within the researcher publication; it is not an independently accessed vendor award record. The quote uses only $. USD is a contextual currency inference from the official OSS VRP rules (currency-context), whose Reward amounts section explicitly denominates discretionary bonuses in USD. Those living rules were reviewed on October 3, 2026, after the January 28 award; their wording at award time was not established. They are denomination context only, not proof of this individual award or settlement. No bonus is established or added.

Primary researcher award and timeline reread; official OSS VRP rules read for contextual denomination only. Award distinguished from program maximums and aggregate earnings. No vulnerability testing performed.

  • The reward is an actual award reported in a primary researcher account; payment settlement was not independently audited.
  • USD is contextually inferred from later program-level denomination wording, not explicitly stated in the quoted individual award. No conflicting denomination was identified in the reviewed sources.

Recorded timeline

Published
2026-03-03explicit
Public Disclosure
2026-03-03explicit · Publication of this write-up; earliest disclosure elsewhere was not independently established.
Reported
2025-12-11explicit
Awarded
2026-01-28explicit
Fixed
2025-12-21explicit · Researcher timeline says the report was marked fixed on this date; deployment timing and patch effectiveness were not independently verified.
Mitigated
2025-12-12explicit · Researcher timeline records disabling the workflow as mitigation.

Related visual models

Sources and provenance

  1. Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning Adnan Khan · reviewed 2026-10-03
  2. Google Open Source Software Vulnerability Reward Program Rules — Reward amounts Google · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software