cockroachdb / cockroachdb/pebble

Security report — possible pull_request_target + checkout-head RCE (please contact privately)

Open
#6,062 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
6k
Forks
584
Avg merge
16h 35m
Merged PRs (30d)
5

Description

Hi —

Automated security scan flagged a `pull_request_target` workflow in your repo that checks out the PR's head SHA. This is the classic GitHub Actions RCE pattern: an external contributor can submit a PR that adds arbitrary code, the workflow runs that code with access to your repository secrets.

I'm not posting the specific file/line here for responsible-disclosure reasons.

Please contact me at **Raffa@Lictor-AI.com** and I'll send the exact workflow file + line + a 2-line patch.

A note: this came from an automated scan I manually verified before reaching out. If we're wrong, please reply and we'll close out.

Want this scan for your own project? Free, takes 60s: **https://lictorai.com/scan**

— Raffa
Lictor AI · https://lictorai.com

Jira issue: PEBBLE-1444

Contributor guide

No contributing guide indexed for this repository

Research direction

The report withholds the workflow file and line, so start by reviewing the repository's pull_request_target workflows and contacting the reporter for the exact location and reproduction details. Verify whether a PR head SHA is checked out and whether untrusted code can access secrets; done means the exposure is confirmed and the workflow is safely corrected, with validation of the relevant workflow checks.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.