Code pipeline at risk after GitHub flaw exposed


Buddies, associates? One happy family?
A traditional dish called zongzi is served during China’s Dragon Boat Festival, which falls in June. It is a rice…
Divina credited the firm’s achievements to its members, thanking them for their ‘hard work, dedication, teamwork, and…
‘Sec. Vince Dizon, please explain how this finding of your own team should not be flagged as a ghost project in Taguig.’
Tenable has uncovered a critical vulnerability in a Microsoft GitHub repository that could allow attackers to execute code and access sensitive credentials, exposing weaknesses in modern software pipelines. The flaw, rated 9.3 under CVSSv4, highlights growing risks in CI/CD environments as part of the broader attack surface.
Researchers found the issue in the Windows-driver-samples repository, where a simple Python injection could be triggered through a public GitHub issue. Once activated, the automated workflow would run malicious code, enabling attackers to extract tokens and potentially gain write-level access to the repository — opening the door to supply chain compromise.
Tenable warned that organizations must treat CI/CD pipelines as critical infrastructure, urging stricter access controls, tighter permission settings and regular audits of automated workflows to prevent similar exploits and large-scale downstream impact.