Threat reportSupply ChainTL-2026-1535

JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn Request' Vulnerabilities Across Ansible, QGIS, Eclipse Theia, Typst, SDKMAN, Telepresence, Tencent, Ceph & More (CVE-2026-24480, CVE-2026-1699)

criticalACTIVE

JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn (TL-2026-1535), also tracked as RepoHunter CI/CD Disclosure, is a critical-severity supply-chain compromise scored CVSS 8.8, first published 2026-03-05. It has no confirmed attribution, affects Red Hat / Ansible ansible.platform, references 2 CVEs (CVE-2026-24480, CVE-2026-1699), maps to 19 MITRE ATT&CK techniques (T1036, T1053, T1059), and is covered by 9 detection rules and 22 indicators of compromise.

CVSS
8.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-1535

Threat ID
TL-2026-1535
Also known as
RepoHunter CI/CD Disclosure, Shai-Hulud 3.0 Preemption, 13 Pwn Requests
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, critical-infrastructure, open-source-ecosystem, software-supply-chain, research-and-education
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

Malware and tooling: RepoHunter, hackerbot-claw

How JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn works

JFrog's AI-driven security research tool RepoHunter (built by Barak Haryati) discovered 13 critical/high/medium CI/CD workflow vulnerabilities (10 Critical, 2 High, 1 Medium) across major open-source projects, all rooted in unsafe use of GitHub Actions' pull_request_target trigger combined with checkout of untrusted PR head code. Exploitation would let any external contributor achieve remote code execution in the base-repository CI context and exfiltrate GITHUB_TOKEN, npm/PyPI/Azure package-publishing tokens, and cross-repo deployment credentials -- the same 'pwn request' technique class behind the prior Shai-Hulud npm worm and the Nx/S1ngularity supply-chain incident. JFrog disclosed all findings responsibly with a ~3-month coordinated window; patches have shipped for the confirmed CVEs (QGIS, Eclipse Theia Website) and GHSA advisories (Ansible, SDKMAN, Telepresence, Typst, Tencent, Ceph, Parse-community, TC39, P4, Petgraph, Xorbitsai).

JFrog's Senior Director of Product Security, Barak Haryati, built RepoHunter, an AI-driven security research bot that automatically crawls open-source GitHub repositories, statically analyzes GitHub Actions workflow configurations, identifies patterns where untrusted external input (pull request branch names, file contents, commit messages, PR titles) reaches privileged execution contexts, and validates exploitability using AI-generated proof-of-concept scenarios. Over a multi-month campaign, RepoHunter surfaced 13 confirmed critical CI/CD takeover vulnerabilities in high-profile OSS projects: Ansible (ansible.platform, GHSA-fwqj-x86q-prmq), P4 Language (GHSA-6cw7-hxfh-8x94), Petgraph, QGIS (CVE-2026-24480 / GHSA-7h99-4f97-h6rw), SDKMAN (GHSA-cprm-c872-3fw7), tc39/proposal-amount (GHSA-43vf-c68r-43mr), Telepresence/CNCF (GHSA-gc3r-m7gq-495f), Typst (GHSA-j5gp-pf74-5pj6), Xorbitsai, Eclipse Theia Website (CVE-2026-1699), Tencent (GHSA-c44p-qr97-jccv), Ceph (GHSA-p433-fp4g-pc2c), and Parse-community (GHSA-6w8g-mgvv-3fcj).

The unifying root cause is the GitHub Actions 'pwn request' anti-pattern: a workflow triggers on pull_request_target (which runs in the base repository's security context, with full access to repository secrets and a GITHUB_TOKEN scoped to the base repo) but then explicitly checks out and executes the pull request's HEAD commit -- code fully controlled by the PR author, who may be an untrusted, first-time external contributor. This differs from the safer pull_request trigger, which runs in a sandboxed fork context with a read-only, minimally-scoped token.

Three distinct execution primitives were observed across the 13 findings: (1) test-based execution, where PR-supplied test files (Rust .rs files in Typst, npm test scripts in Theia) are executed directly by the CI test runner; (2) build-script execution, where PR-controlled build tooling (a modified gradlew wrapper in SDKMAN, npm install/build in Theia, Makefile targets in Telepresence, cargo in Petgraph) runs attacker-supplied commands during the normal build process; and (3) config/branch injection, where unsanitized metadata such as branch names or a malicious .pre-commit-config.yaml (QGIS) is interpolated into shell commands or hook definitions, yielding command injection.

A compounding factor documented across multiple advisories is actions/checkout's historical default of persist-credentials: true, which writes the ephemeral GITHUB_TOKEN into .git/config inside the runner workspace -- meaning any RCE primitive, however achieved, can trivially read the token back out of the git configuration file rather than needing to specifically target environment variables. GitHub subsequently changed the safer defaults for pull_request_target checkouts in its June 2026 Actions checkout update in direct response to this vulnerability class.

Per-project impact: Ansible's ansible.platform workflow exposed both a highly-privileged GITHUB_TOKEN (contents:write, actions:write, packages:write, pull-requests:write, deployments:write, attestations:write, pages:write) and a custom AAP_GATEWAY_REPO_TOKEN enabling lateral movement into other Ansible Automation Platform repositories, risking millions of downstream package downloads. QGIS's 'pre-commit checks' workflow allowed an attacker to add a malicious .pre-commit-config.yaml defining an arbitrary-execution hook, achieving RCE with a write-scoped GITHUB_TOKEN able to push commits, modify branches, and tamper with QGIS release artifacts consumed by governments, research institutions, and Linux distribution packagers. Eclipse Theia's Website repository preview.yml workflow exposed GITHUB_TOKEN plus DEPLOY_PREVIEW_TOKEN and NODE_AUTH_TOKEN, enabling secret exfiltration, malicious npm package publication under the eclipse-theia organization, and direct modification of the official Theia website. Typst's test_pr.yml exposed AZURE_PACKAGE_CREDENTIALS, GH_PRIVATE_KEY, GH_APP_ID, and GH_INSTALLATION_ID -- a GitHub App private key permitting on-demand minting of installation access tokens scoped across the entire Typst GitHub organization, the most severe blast radius among the 13 findings. SDKMAN's pull-requests.yml allowed a modified gradlew wrapper to execute with a contents:write GITHUB_TOKEN, permitting malicious commits/release tampering distributed to the JVM developer ecosystem. Telepresence's image-scan workflow (CNCF project) permitted RCE and write access via a crafted Makefile.

JFrog frames this disclosure explicitly against the 'Shai-Hulud' npm worm (August 2025) and its predecessor S1ngularity attack against the Nx build-system project, in which an unsanitized PR title reaching a pull_request_target workflow leaked roughly 83,000 secrets -- establishing that this exact technique class has already produced a real self-propagating supply-chain worm, elevating the credibility and urgency of these 13 preemptive findings. JFrog also contrasts its defensive RepoHunter research against a separate, unrelated malicious campaign it names 'hackerbot-claw,' which it says used similar AI-assisted reconnaissance techniques offensively to compromise repositories at Microsoft, DataDog, CNCF, and Trivy -- illustrating that the same automated-CI-recon capability is now being weaponized independently of JFrog's disclosure.

All 13 findings were disclosed under coordinated/responsible disclosure with roughly a three-month remediation window before JFrog's public blog post. Confirmed fixes: Ansible (PR #103, patched release 2.5.20260109), QGIS (commit 76a693cd91650f9b4e83edac525e5e4f90d954e9), Eclipse Theia Website (commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560). Remediation guidance from JFrog and GitHub: treat pull_request_target with extreme caution; never explicitly checkout PR head refs under that trigger; use pull_request instead wherever privileged actions are not required; apply least-privilege permissions blocks per workflow; sanitize all untrusted metadata (branch names, PR titles, file contents) before use in shell contexts; disable persist-credentials when the token is not needed post-checkout; and separate privileged automation (deploy, publish, release) into workflows that never execute untrusted code.

MITRE ATT&CK techniques used in TL-2026-1535

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter

Discovery

T1069 Permission Groups Discovery; T1526 Cloud Service Discovery

Privilege Escalation

T1078 Valid Accounts

Command and Control

T1102 Web Service

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

initial-access

T1195 Supply Chain Compromise

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Lateral Movement

T1550 Use Alternate Authentication Material

Impact

T1565 Data Manipulation

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1585 Establish Accounts

Reconnaissance

T1593 Search Open Websites/Domains

Affected products and versions in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

  • Red Hat / Ansible — ansible.platform
    Vulnerable versions: 2.5.20251114
    Fixed in: 2.5.20260109
  • P4 Language Consortium — p4lang (P4)
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • petgraph — petgraph
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • QGIS.org — QGIS
    Vulnerable versions: workflow config prior to commit 76a693c
    Fixed in: commit 76a693cd91650f9b4e83edac525e5e4f90d954e9 and later
  • SDKMAN — sdkman-cli
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • TC39 / Ecma International — tc39/proposal-amount
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • CNCF — Telepresence
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • Typst — typst/packages
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • Xorbitsai — Xorbits
    Vulnerable versions: workflow config prior to fix
    Fixed in: current
  • Eclipse Foundation — Eclipse Theia - Website
    Vulnerable versions: workflow config prior to commit 2fb0cc4
    Fixed in: commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560 and later

Remediation for JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

Patches

  • Ansible ansible.platform: patched in release 2.5.20260109 (PR #103)
  • QGIS: patched via commit 76a693cd91650f9b4e83edac525e5e4f90d954e9
  • Eclipse Theia Website: patched via commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560
  • SDKMAN, Telepresence, Typst, Tencent, Ceph, Parse-community, TC39, P4 Language, Petgraph, Xorbitsai: workflow fixes shipped per respective GHSA advisories, no upstream software version change required

Immediate actions

  • Audit every workflow in the repository for the pull_request_target trigger combined with an explicit checkout of the PR head SHA/ref
  • Replace pull_request_target with pull_request wherever privileged secrets or write-scoped tokens are not strictly required
  • Set persist-credentials: false on actions/checkout steps that do not need to push back to the repository
  • Rotate any GITHUB_TOKEN-derived credentials, npm/PyPI/Azure publishing tokens, and GitHub App private keys used in affected workflows
  • Review recent CI run logs for unexpected outbound network calls, unexpected package publishes, or unrecognized commits/branches originating from fork PRs

Workarounds

  • Temporarily disable the affected workflow (image-scan, pull-requests.yml, preview.yml, test_pr.yml, pre-commit checks, integration.yml) for pull requests originating from forks until the permissions/checkout logic is fixed

Longer-term hardening

  • Apply explicit least-privilege 'permissions:' blocks to every workflow (default to contents: read)
  • Move privileged operations (publish, deploy, release, comment-on-PR) into a separate workflow_run-triggered job that never checks out untrusted PR code
  • Sanitize all untrusted, attacker-controllable strings (branch names, PR titles, commit messages, file paths) before interpolating into shell commands or config files
  • Adopt GitHub's updated safer actions/checkout defaults for pull_request_target (June 2026 changelog) across all repositories
  • Require maintainer approval for first-time-contributor workflow runs; enable 'Require approval for all outside collaborators'

CVEs associated with JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

CVE-2026-24480, CVE-2026-1699

Weaknesses (CWE) in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

CWE-829, CWE-78, CWE-94, CWE-284

Timeline of JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

  • Remaining GHSA advisories published for the balance of the 13 findings: P4 Language (GHSA-6cw7-hxfh-8x94), Petgraph, TC39/proposal-amount (GHSA-43vf-c68r-43mr), Xorbitsai, Tencent (GHSA-c44p-qr97-jccv), Ceph (GHSA-p433-fp4g-pc2c), and Parse-community (GHSA-6w8g-mgvv-3fcj).
  • GHSA-cprm-c872-3fw7 published for sdkman/sdkman-cli: RCE via a PR-modified gradlew wrapper executed under pull_request_target with a contents:write GITHUB_TOKEN.
  • GHSA-j5gp-pf74-5pj6 published for typst/packages: test_pr.yml pull_request_target vulnerability exposing AZURE_PACKAGE_CREDENTIALS, GH_PRIVATE_KEY, GH_APP_ID, and GH_INSTALLATION_ID, the highest-blast-radius finding among the 13 (org-wide GitHub App token minting).
  • GHSA-gc3r-m7gq-495f published for telepresenceio/telepresence: unsafe pull_request_target allowing arbitrary code execution and write access via a crafted Makefile in the image-scan workflow.
  • CVE-2026-1699 (CWE-829) assigned for the Eclipse Theia Website repository's preview.yml pull_request_target vulnerability, exposing GITHUB_TOKEN, DEPLOY_PREVIEW_TOKEN, and NODE_AUTH_TOKEN.
  • GHSA-fwqj-x86q-prmq published for ansible/ansible.platform: RCE via unsafe pull_request_target in .github/workflows/integration.yml, exposing GITHUB_TOKEN and AAP_GATEWAY_REPO_TOKEN.
  • Ansible ansible.platform patched release 2.5.20260109 shipped, remediating GHSA-fwqj-x86q-prmq via PR #103.
  • GHSA-7h99-4f97-h6rw published for qgis/QGIS: critical validated RCE and repository takeover via the 'pre-commit checks' GitHub Actions workflow (CVE-2026-24480).
  • CVE-2026-24480 formally published in NVD for the QGIS pull_request_target RCE vulnerability, CVSS 4.0 base score 8.7 (later scored 8.8 under CVSS 3.1 by downstream trackers).
  • JFrog publishes 'How Our AI Bot Stopped the Next Shai-Hulud,' publicly disclosing all 13 RepoHunter-discovered CI/CD vulnerabilities after coordinated remediation, alongside companion technical deep-dive 'pull_request_target Exploitation - Part 1' on research.jfrog.com.
  • GitHub ships safer actions/checkout defaults for pull_request_target-triggered workflows, directly citing this vulnerability class, changing default checkout behavior to reduce blast radius of future pwn-request findings.

Sources cited for JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn

Detection coverage for TL-2026-1535

As of 2026-03-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1535 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats