vulns.co
/
GKData.io MCP

SCSoftware supply-chain security · 1 min read

GitHub Actions trust depended on invalid repository references

A reference-validation flaw crossed the GitHub Actions trust boundary and earned USD 25,000.

Read the primary source SCSoftware supply-chain securityReviewed 2026-10-02

Root cause

Object validation differed between creation and mutation; automation relied on a branch-type invariant that was not consistently enforced.

Demonstrated impact

Repository secrets and write authority could become available to an unauthorized workflow.

Lessons for review

  • Enforce security invariants at every mutation and at their privileged consumers.
  • Keep repository secrets confined to explicitly trusted execution contexts.

Award and evidence

USD 25,000Bug Bounty · Researcher Reported

Single finding; the later 2022 follow-up earned USD 7,500 and is excluded.

Primary public source read; individual award and source provenance verified. No target testing or exploit reproduction performed.

  • Award is reported by the cited source; cash settlement is not independently audited.

Recorded timeline

Published
2021-03-17explicit
Reported
2021-02-04explicit
Awarded
2021-03-03explicit
Fixed
2021-03-02explicit · GitHub Enterprise Server 3.0.1 release; github.com was fixed earlier in February, without an exact final timestamp in the source.

Related visual models

Sources and provenance

  1. Stealing arbitrary GitHub Actions secrets Teddy Katz · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software