Skip to content

Security report — possible pull_request_target + checkout-head RCE (please contact privately) #263

@Raffa-jarrl

Description

@Raffa-jarrl

Hi —

Automated security scan flagged a pull_request_target workflow in your repo that checks out the PR's head SHA / ref. This is the pattern of the classic GitHub Actions RCE — but whether it's actually exploitable depends on your guards (label gates, approved-ci checks, head-vs-base ownership checks, etc).

I'm not claiming we verified exploitability — we verified the pattern exists. Please review your workflow's guards and confirm. If they're sufficient, this is a non-issue and you can close.

If you'd like the exact workflow file + line we flagged, reply here or email Raffa@Lictor-AI.com.

— Raffa
Lictor AI · https://lictorai.com

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions