chiprook
← Security
SecurityOctober 12, 2026, 03:18

DuckDuckGo CI/CD RCE could have backdoored every browser

Researcher 6r1ff1n found that the semver-label.yml workflow in duckduckgo/content-scope-scripts used pull_request_target with no fork checks, letting any GitHub user run code on DuckDuckGo's CI runner. Stolen secrets, including a GITHUB_TOKEN with pull-requests: write, could have pushed a poisoned unsigned release to every DuckDuckGo browser.

DuckDuckGo CI/CD RCE could have backdoored every browser
#DuckDuckGo#GitHub
Read next
Security

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

Security

Agent skill harvesting browser credentials had 60,000 GitHub stars

Security

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Security

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites