View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Permissive GitHub Actions workflows expose tokens and secrets

๐Ÿšจ ACTIVE EXPLOITATION

๐Ÿ“‹ ADVISORIES

  • Permissive GitHub Actions workflows expose tokens and secrets to attackers
    Attackers can abuse permissive GitHub Actions workflows to steal tokens and secrets.
    • GitHub Actions users and organizations are affected.
    • Pull-request workflows, third-party actions, and runner environments can expose GITHUB_TOKEN credentials, secrets, or build outputs.
    • Contributor-controlled code can run in a privileged workflow and access tokens or secrets.
    • Compromised actions or runner environments can also read credentials and alter build artifacts.
      ๐Ÿ“Ž Coverage: clearpathsecurity.co.uk ยท ๐Ÿ‘ via securityboulevard.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-78306 โ€” CVSS 8.5 โ€” DJI Drone Bluetooth Interface Unauthenticated DUML Command ExecutionDJI drone...

  • CVE-2026-78321 โ€” CVSS 6.0 โ€” DJI Drone HTTP Media Server Denial of Service via Connection Pool ExhaustionT...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check