vulns.co
/
GKData.io MCP

SCSoftware supply-chain security · 2 min read

GitHub runner-image builds shared persistent infrastructure with untrusted workflows

An isolation misconfiguration exposed runner-image build infrastructure; the researcher reports a $20,000 payment.

Read the primary source SCSoftware supply-chain securityReviewed 2026-10-02

Root cause

Contributor status was treated as sufficient trust for workflows using persistent self-hosted infrastructure. The researcher connected approval policy, runner reuse and privileged build context to identify a boundary failure between outside contributions and trusted image production.

Demonstrated impact

With contributor access under the affected configuration, the researcher demonstrated infrastructure access and build-secret exposure. Downstream compromise of distributed runner images remained a modeled consequence: intervening production controls were unknown.

Lessons for review

  • Separate untrusted contribution processing from privileged build infrastructure and secrets.
  • Bind review to the workflow being executed; prior contribution history is not continuing authorization.
  • Use isolated disposable execution environments and independently verify release provenance.

Award and evidence

USD 20,000Bug Bounty · Researcher Reported

One report. GitHub’s official January 2017 article (updated June 2021) explicitly denominates standard bounties in USD; current platform guidelines corroborate context, not this individual award. Earlier researcher post explicitly says paid.

Read primary public disclosures and corroborating sources; checked individual award scope. No target interaction or exploit reproduction.

  • Payment is researcher-reported, not independently audited.
  • The reviewed HackerOne currency guideline is the current page, not a preserved 2023 policy snapshot.
  • Resolution on November 14 does not establish an exact final remediation date.

Recorded timeline

Published
2023-12-20explicit · Detailed article date.
Public Disclosure
2023-12-16explicit · Earlier public summary; not the detailed article date.
Reported
2023-07-22explicit
Awarded
2023-11-14explicit
Paid
2023-11-14explicit
Mitigated
2023-07-25explicit · Detailed timeline: initial mitigations. Earlier summary says immediate fixes July 26; final technical fix date remains unknown.

Sources and provenance

  1. One Supply Chain Attack to Rule Them All - Poisoning GitHub's Runner Images Adnan Khan · reviewed 2026-10-02
  2. Welcome to my blog - there is more to come! Adnan Khan · reviewed 2026-10-02
  3. Vulnerability Disclosure Guidelines HackerOne · reviewed 2026-10-02
  4. Bug bounty anniversary promotion: Bigger bounties in January and February Neil Matatall / GitHub · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software