Lightning-AI / Lightning-AI/litgpt

Secrets exfiltration vulnerability

Open
#2,090 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
13.7k
Forks
1.5k
Avg merge
15h 37m
Merged PRs (30d)
1

Description

Hi,
We found a critical vulnerability in one of the CI workflows in this repo. We already submitted a GHSA to securely disclose all the information and the POC to reproduce the issue.
The repository is still vulnerable, and exploiting the vulnerability, an attacker could exfiltrate secrets and a highly privileged GITHUB_TOKEN to revert the overall repo.

Let me know if we can provide any other information to fix it.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the repository's CI workflows and the GHSA and proof of concept referenced in the issue to identify the vulnerable path. Done means the vulnerability is remediated and secrets and the highly privileged GITHUB_TOKEN can no longer be exfiltrated or misused; verify the workflow behavior against the disclosed reproduction.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.