Lightning-AI / Lightning-AI/litgpt
Secrets exfiltration vulnerability
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 13.7k
- Forks
- 1.5k
- Avg merge
- 15h 37m
- Merged PRs (30d)
- 1
Description
Hi,
We found a critical vulnerability in one of the CI workflows in this repo. We already submitted a GHSA to securely disclose all the information and the POC to reproduce the issue.
The repository is still vulnerable, and exploiting the vulnerability, an attacker could exfiltrate secrets and a highly privileged GITHUB_TOKEN to revert the overall repo.
Let me know if we can provide any other information to fix it.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the repository's CI workflows and the GHSA and proof of concept referenced in the issue to identify the vulnerable path. Done means the vulnerability is remediated and secrets and the highly privileged GITHUB_TOKEN can no longer be exfiltrated or misused; verify the workflow behavior against the disclosed reproduction.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100