Rust's Miri leaked CI secrets via GitHub Actions caches
The Rust project published an advisory on 21 September 2026: Miri, Rust's undefined-behavior interpreter, wrote every environment variable into the target/ directory, which most Rust projects cache in GitHub Actions. Secrets passed to a CI step could land in the cache and be restored by a later pull request run. Fixed in the nightly toolchain dated 22 September 2026; no CVE was assigned.
- Miri persisted all environment variables into target/, including CI secrets
- GitHub Actions cache scoping lets PR runs restore caches from main
- Nightly from 22 September 2026 keeps only CARGO_* and OUT_DIR
- Users should update the toolchain, purge caches and rotate secrets
Read next
Security