cockroachdb / cockroachdb/pebble
Security report — possible pull_request_target + checkout-head RCE (please contact privately)
- Dominant language
- Go
- Stars
- 6k
- Forks
- 584
- Avg merge
- 16h 35m
- Merged PRs (30d)
- 5
Description
Hi —
Automated security scan flagged a `pull_request_target` workflow in your repo that checks out the PR's head SHA. This is the classic GitHub Actions RCE pattern: an external contributor can submit a PR that adds arbitrary code, the workflow runs that code with access to your repository secrets.
I'm not posting the specific file/line here for responsible-disclosure reasons.
Please contact me at **Raffa@Lictor-AI.com** and I'll send the exact workflow file + line + a 2-line patch.
A note: this came from an automated scan I manually verified before reaching out. If we're wrong, please reply and we'll close out.
Want this scan for your own project? Free, takes 60s: **https://lictorai.com/scan**
— Raffa
Lictor AI · https://lictorai.com
Jira issue: PEBBLE-1444
Contributor guide
No contributing guide indexed for this repository
Research direction
The report withholds the workflow file and line, so start by reviewing the repository's pull_request_target workflows and contacting the reporter for the exact location and reproduction details. Verify whether a PR head SHA is checked out and whether untrusted code can access secrets; done means the exposure is confirmed and the workflow is safely corrected, with validation of the relevant workflow checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100