Skip to content

PoC: pull_request_target executes PR code with secrets present#4

Closed
IamRohanBodas wants to merge 2 commits intozendesk:masterfrom
IamRohanBodas:poc-pr-target
Closed

PoC: pull_request_target executes PR code with secrets present#4
IamRohanBodas wants to merge 2 commits intozendesk:masterfrom
IamRohanBodas:poc-pr-target

Conversation

@IamRohanBodas
Copy link

@IamRohanBodas IamRohanBodas commented Jan 19, 2026

Safe PoC demonstrating that attacker-controlled PR code executes in a pull_request_target workflow with secrets available.

@IamRohanBodas
Copy link
Author

Hi Team!Could someone please review this when time permits? Thanks in advance!

1 similar comment
@IamRohanBodas
Copy link
Author

Hi Team!Could someone please review this when time permits? Thanks in advance!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant