Audit of 60 public GitHub Actions workflows finds 6 exploitable via pull_request_target
A study of two samples of 30 public GitHub Actions workflows each found that 6 of 60 (10%) are exploitable through the pull_request_target trigger, which runs with the base repository's secrets and write token while also checking out and executing code from a fork. Working mitigations observed in real repositories include an environment requiring approval, a maintainer label gate for fork PRs, and a separate trusted checkout of the base branch.
- 6 of 60 public workflows (10%) are exploitable via pull_request_target
- Exploitation needs three ingredients: the trigger, a checkout of the PR code, and its execution
- The allow-unsafe-pr-checkout: true flag is an acknowledgement of risk, not a mitigation
- Working fixes: approval-gated environment, maintainer label, trusted base-branch checkout
Read next
Software