Skip to content

Security report — possible pull_request_target + checkout-head RCE (please contact privately) #263

Description

@Raffa-jarrl

Hi —

Automated security scan flagged a pull_request_target workflow in your repo that checks out the PR's head SHA / ref. This is the pattern of the classic GitHub Actions RCE — but whether it's actually exploitable depends on your guards (label gates, approved-ci checks, head-vs-base ownership checks, etc).

I'm not claiming we verified exploitability — we verified the pattern exists. Please review your workflow's guards and confirm. If they're sufficient, this is a non-issue and you can close.

If you'd like the exact workflow file + line we flagged, reply here or email Raffa@Lictor-AI.com.

— Raffa
Lictor AI · https://lictorai.com

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions