GitHub Actions Workflow Composition Exploited Across 300+ Open-Source Repos
The Cordyceps vulnerability class reveals that attackers can chain GitHub Actions primitives—specifically pull_request_target and workflow_run—with command injection and cross-workflow privilege escalation to steal long-lived credentials from high-profile repositories at Microsoft, Google, and Apache. The root cause is not a single bug but a dangerous composition of individually innocuous workflow features that, when combined, create exploitable attack paths invisible to traditional SAST/DAST tools that analyze files in isolation rather than evaluating multi-workflow execution graphs. Because attackers need only a free GitHub account and can harvest non-expiring tokens and cloud credentials, the blast radius extends far beyond the compromised repo into downstream supply chains. This matters because the affected ecosystems—npm, PyPI, crates.io, and Go—underpin millions of production applications globally.
Tactical Insight
Immediate actions
- Audit all workflows using `pull_request_target` and `workflow_run` triggers and restrict them to explicitly trusted branches and actors.
- Rotate any GitHub tokens and cloud credentials exposed in affected repositories immediately, treating them as compromised.
- Pin all third-party GitHub Actions to a specific commit SHA rather than a mutable tag to prevent injection via upstream action tampering.
Configuration hardening
- Set `permissions` blocks to least-privilege (e.g., `read-only`) at the workflow and job level, explicitly denying write or secrets access where not required.
- Enable repository rulesets to require pull request approval before workflows execute in the context of `pull_request_target`.
- Use GitHub's `CODEOWNERS` and branch protection rules to prevent unauthorized modifications to workflow definition files.
Detection measures
- Adopt CI/CD-aware security scanners (e.g., StepSecurity, Zizmor) that perform cross-workflow dataflow analysis rather than single-file SAST evaluation.
- Enable GitHub audit log streaming to a SIEM and alert on anomalous workflow runs, unexpected secret access, or token usage from unfamiliar IP ranges.
- Implement continuous monitoring of Actions workflow changes via policy-as-code tools (e.g., Open Policy Agent) integrated into the merge pipeline.