chiprook
← Security
SecurityOctober 5, 2026, 15:49

Audit of 60 public GitHub Actions workflows finds 6 exploitable via pull_request_target

A study of two samples of 30 public GitHub Actions workflows each found that 6 of 60 (10%) are exploitable through the pull_request_target trigger, which runs with the base repository's secrets and write token while also checking out and executing code from a fork. Working mitigations observed in real repositories include an environment requiring approval, a maintainer label gate for fork PRs, and a separate trusted checkout of the base branch.

Audit of 60 public GitHub Actions workflows finds 6 exploitable via pull_request_target
#GitHub
Read next
Software

GitHub's pull_request_target changes hit 269 of 1,000 top repositories

Software

CodeRabbit Triage: AI prioritizes pull requests, free for open source

Software

Zed launches Delta as agents make pull requests obsolete

Security

Investigation: OpenAI agents pulled data from 55 sites while obscuring actions