Threat reportSupply ChainTL-2026-1535
JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn Request' Vulnerabilities Across Ansible, QGIS, Eclipse Theia, Typst, SDKMAN, Telepresence, Tencent, Ceph & More (CVE-2026-24480, CVE-2026-1699)
JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn (TL-2026-1535), also tracked as RepoHunter CI/CD Disclosure, is a critical-severity supply-chain compromise scored CVSS 8.8, first published 2026-03-05. It has no confirmed attribution, affects Red Hat / Ansible ansible.platform, references 2 CVEs (CVE-2026-24480, CVE-2026-1699), maps to 19 MITRE ATT&CK techniques (T1036, T1053, T1059), and is covered by 9 detection rules and 22 indicators of compromise.
- CVSS
- 8.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1535
- Threat ID
- TL-2026-1535
- Also known as
- RepoHunter CI/CD Disclosure, Shai-Hulud 3.0 Preemption, 13 Pwn Requests
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, critical-infrastructure, open-source-ecosystem, software-supply-chain, research-and-education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
Malware and tooling: RepoHunter, hackerbot-claw
How JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn works
JFrog's AI-driven security research tool RepoHunter (built by Barak Haryati) discovered 13 critical/high/medium CI/CD workflow vulnerabilities (10 Critical, 2 High, 1 Medium) across major open-source projects, all rooted in unsafe use of GitHub Actions' pull_request_target trigger combined with checkout of untrusted PR head code. Exploitation would let any external contributor achieve remote code execution in the base-repository CI context and exfiltrate GITHUB_TOKEN, npm/PyPI/Azure package-publishing tokens, and cross-repo deployment credentials -- the same 'pwn request' technique class behind the prior Shai-Hulud npm worm and the Nx/S1ngularity supply-chain incident. JFrog disclosed all findings responsibly with a ~3-month coordinated window; patches have shipped for the confirmed CVEs (QGIS, Eclipse Theia Website) and GHSA advisories (Ansible, SDKMAN, Telepresence, Typst, Tencent, Ceph, Parse-community, TC39, P4, Petgraph, Xorbitsai).
JFrog's Senior Director of Product Security, Barak Haryati, built RepoHunter, an AI-driven security research bot that automatically crawls open-source GitHub repositories, statically analyzes GitHub Actions workflow configurations, identifies patterns where untrusted external input (pull request branch names, file contents, commit messages, PR titles) reaches privileged execution contexts, and validates exploitability using AI-generated proof-of-concept scenarios. Over a multi-month campaign, RepoHunter surfaced 13 confirmed critical CI/CD takeover vulnerabilities in high-profile OSS projects: Ansible (ansible.platform, GHSA-fwqj-x86q-prmq), P4 Language (GHSA-6cw7-hxfh-8x94), Petgraph, QGIS (CVE-2026-24480 / GHSA-7h99-4f97-h6rw), SDKMAN (GHSA-cprm-c872-3fw7), tc39/proposal-amount (GHSA-43vf-c68r-43mr), Telepresence/CNCF (GHSA-gc3r-m7gq-495f), Typst (GHSA-j5gp-pf74-5pj6), Xorbitsai, Eclipse Theia Website (CVE-2026-1699), Tencent (GHSA-c44p-qr97-jccv), Ceph (GHSA-p433-fp4g-pc2c), and Parse-community (GHSA-6w8g-mgvv-3fcj).
The unifying root cause is the GitHub Actions 'pwn request' anti-pattern: a workflow triggers on pull_request_target (which runs in the base repository's security context, with full access to repository secrets and a GITHUB_TOKEN scoped to the base repo) but then explicitly checks out and executes the pull request's HEAD commit -- code fully controlled by the PR author, who may be an untrusted, first-time external contributor. This differs from the safer pull_request trigger, which runs in a sandboxed fork context with a read-only, minimally-scoped token.
Three distinct execution primitives were observed across the 13 findings: (1) test-based execution, where PR-supplied test files (Rust .rs files in Typst, npm test scripts in Theia) are executed directly by the CI test runner; (2) build-script execution, where PR-controlled build tooling (a modified gradlew wrapper in SDKMAN, npm install/build in Theia, Makefile targets in Telepresence, cargo in Petgraph) runs attacker-supplied commands during the normal build process; and (3) config/branch injection, where unsanitized metadata such as branch names or a malicious .pre-commit-config.yaml (QGIS) is interpolated into shell commands or hook definitions, yielding command injection.
A compounding factor documented across multiple advisories is actions/checkout's historical default of persist-credentials: true, which writes the ephemeral GITHUB_TOKEN into .git/config inside the runner workspace -- meaning any RCE primitive, however achieved, can trivially read the token back out of the git configuration file rather than needing to specifically target environment variables. GitHub subsequently changed the safer defaults for pull_request_target checkouts in its June 2026 Actions checkout update in direct response to this vulnerability class.
Per-project impact: Ansible's ansible.platform workflow exposed both a highly-privileged GITHUB_TOKEN (contents:write, actions:write, packages:write, pull-requests:write, deployments:write, attestations:write, pages:write) and a custom AAP_GATEWAY_REPO_TOKEN enabling lateral movement into other Ansible Automation Platform repositories, risking millions of downstream package downloads. QGIS's 'pre-commit checks' workflow allowed an attacker to add a malicious .pre-commit-config.yaml defining an arbitrary-execution hook, achieving RCE with a write-scoped GITHUB_TOKEN able to push commits, modify branches, and tamper with QGIS release artifacts consumed by governments, research institutions, and Linux distribution packagers. Eclipse Theia's Website repository preview.yml workflow exposed GITHUB_TOKEN plus DEPLOY_PREVIEW_TOKEN and NODE_AUTH_TOKEN, enabling secret exfiltration, malicious npm package publication under the eclipse-theia organization, and direct modification of the official Theia website. Typst's test_pr.yml exposed AZURE_PACKAGE_CREDENTIALS, GH_PRIVATE_KEY, GH_APP_ID, and GH_INSTALLATION_ID -- a GitHub App private key permitting on-demand minting of installation access tokens scoped across the entire Typst GitHub organization, the most severe blast radius among the 13 findings. SDKMAN's pull-requests.yml allowed a modified gradlew wrapper to execute with a contents:write GITHUB_TOKEN, permitting malicious commits/release tampering distributed to the JVM developer ecosystem. Telepresence's image-scan workflow (CNCF project) permitted RCE and write access via a crafted Makefile.
JFrog frames this disclosure explicitly against the 'Shai-Hulud' npm worm (August 2025) and its predecessor S1ngularity attack against the Nx build-system project, in which an unsanitized PR title reaching a pull_request_target workflow leaked roughly 83,000 secrets -- establishing that this exact technique class has already produced a real self-propagating supply-chain worm, elevating the credibility and urgency of these 13 preemptive findings. JFrog also contrasts its defensive RepoHunter research against a separate, unrelated malicious campaign it names 'hackerbot-claw,' which it says used similar AI-assisted reconnaissance techniques offensively to compromise repositories at Microsoft, DataDog, CNCF, and Trivy -- illustrating that the same automated-CI-recon capability is now being weaponized independently of JFrog's disclosure.
All 13 findings were disclosed under coordinated/responsible disclosure with roughly a three-month remediation window before JFrog's public blog post. Confirmed fixes: Ansible (PR #103, patched release 2.5.20260109), QGIS (commit 76a693cd91650f9b4e83edac525e5e4f90d954e9), Eclipse Theia Website (commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560). Remediation guidance from JFrog and GitHub: treat pull_request_target with extreme caution; never explicitly checkout PR head refs under that trigger; use pull_request instead wherever privileged actions are not required; apply least-privilege permissions blocks per workflow; sanitize all untrusted metadata (branch names, PR titles, file contents) before use in shell contexts; disable persist-credentials when the token is not needed post-checkout; and separate privileged automation (deploy, publish, release) into workflows that never execute untrusted code.
MITRE ATT&CK techniques used in TL-2026-1535
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
Discovery
T1069 Permission Groups Discovery; T1526 Cloud Service Discovery
Privilege Escalation
Command and Control
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
initial-access
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
Lateral Movement
T1550 Use Alternate Authentication Material
Impact
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
Affected products and versions in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
- Red Hat / Ansible — ansible.platform
Vulnerable versions: 2.5.20251114
Fixed in: 2.5.20260109 - P4 Language Consortium — p4lang (P4)
Vulnerable versions: workflow config prior to fix
Fixed in: current - petgraph — petgraph
Vulnerable versions: workflow config prior to fix
Fixed in: current - QGIS.org — QGIS
Vulnerable versions: workflow config prior to commit 76a693c
Fixed in: commit 76a693cd91650f9b4e83edac525e5e4f90d954e9 and later - SDKMAN — sdkman-cli
Vulnerable versions: workflow config prior to fix
Fixed in: current - TC39 / Ecma International — tc39/proposal-amount
Vulnerable versions: workflow config prior to fix
Fixed in: current - CNCF — Telepresence
Vulnerable versions: workflow config prior to fix
Fixed in: current - Typst — typst/packages
Vulnerable versions: workflow config prior to fix
Fixed in: current - Xorbitsai — Xorbits
Vulnerable versions: workflow config prior to fix
Fixed in: current - Eclipse Foundation — Eclipse Theia - Website
Vulnerable versions: workflow config prior to commit 2fb0cc4
Fixed in: commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560 and later
Remediation for JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
Patches
- Ansible ansible.platform: patched in release 2.5.20260109 (PR #103)
- QGIS: patched via commit 76a693cd91650f9b4e83edac525e5e4f90d954e9
- Eclipse Theia Website: patched via commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560
- SDKMAN, Telepresence, Typst, Tencent, Ceph, Parse-community, TC39, P4 Language, Petgraph, Xorbitsai: workflow fixes shipped per respective GHSA advisories, no upstream software version change required
Immediate actions
- Audit every workflow in the repository for the pull_request_target trigger combined with an explicit checkout of the PR head SHA/ref
- Replace pull_request_target with pull_request wherever privileged secrets or write-scoped tokens are not strictly required
- Set persist-credentials: false on actions/checkout steps that do not need to push back to the repository
- Rotate any GITHUB_TOKEN-derived credentials, npm/PyPI/Azure publishing tokens, and GitHub App private keys used in affected workflows
- Review recent CI run logs for unexpected outbound network calls, unexpected package publishes, or unrecognized commits/branches originating from fork PRs
Workarounds
- Temporarily disable the affected workflow (image-scan, pull-requests.yml, preview.yml, test_pr.yml, pre-commit checks, integration.yml) for pull requests originating from forks until the permissions/checkout logic is fixed
Longer-term hardening
- Apply explicit least-privilege 'permissions:' blocks to every workflow (default to contents: read)
- Move privileged operations (publish, deploy, release, comment-on-PR) into a separate workflow_run-triggered job that never checks out untrusted PR code
- Sanitize all untrusted, attacker-controllable strings (branch names, PR titles, commit messages, file paths) before interpolating into shell commands or config files
- Adopt GitHub's updated safer actions/checkout defaults for pull_request_target (June 2026 changelog) across all repositories
- Require maintainer approval for first-time-contributor workflow runs; enable 'Require approval for all outside collaborators'
CVEs associated with JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
Weaknesses (CWE) in JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
Timeline of JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
- Remaining GHSA advisories published for the balance of the 13 findings: P4 Language (GHSA-6cw7-hxfh-8x94), Petgraph, TC39/proposal-amount (GHSA-43vf-c68r-43mr), Xorbitsai, Tencent (GHSA-c44p-qr97-jccv), Ceph (GHSA-p433-fp4g-pc2c), and Parse-community (GHSA-6w8g-mgvv-3fcj).
- GHSA-cprm-c872-3fw7 published for sdkman/sdkman-cli: RCE via a PR-modified gradlew wrapper executed under pull_request_target with a contents:write GITHUB_TOKEN.
- GHSA-j5gp-pf74-5pj6 published for typst/packages: test_pr.yml pull_request_target vulnerability exposing AZURE_PACKAGE_CREDENTIALS, GH_PRIVATE_KEY, GH_APP_ID, and GH_INSTALLATION_ID, the highest-blast-radius finding among the 13 (org-wide GitHub App token minting).
- GHSA-gc3r-m7gq-495f published for telepresenceio/telepresence: unsafe pull_request_target allowing arbitrary code execution and write access via a crafted Makefile in the image-scan workflow.
- CVE-2026-1699 (CWE-829) assigned for the Eclipse Theia Website repository's preview.yml pull_request_target vulnerability, exposing GITHUB_TOKEN, DEPLOY_PREVIEW_TOKEN, and NODE_AUTH_TOKEN.
- GHSA-fwqj-x86q-prmq published for ansible/ansible.platform: RCE via unsafe pull_request_target in .github/workflows/integration.yml, exposing GITHUB_TOKEN and AAP_GATEWAY_REPO_TOKEN.
- Ansible ansible.platform patched release 2.5.20260109 shipped, remediating GHSA-fwqj-x86q-prmq via PR #103.
- GHSA-7h99-4f97-h6rw published for qgis/QGIS: critical validated RCE and repository takeover via the 'pre-commit checks' GitHub Actions workflow (CVE-2026-24480).
- CVE-2026-24480 formally published in NVD for the QGIS pull_request_target RCE vulnerability, CVSS 4.0 base score 8.7 (later scored 8.8 under CVSS 3.1 by downstream trackers).
- JFrog publishes 'How Our AI Bot Stopped the Next Shai-Hulud,' publicly disclosing all 13 RepoHunter-discovered CI/CD vulnerabilities after coordinated remediation, alongside companion technical deep-dive 'pull_request_target Exploitation - Part 1' on research.jfrog.com.
- GitHub ships safer actions/checkout defaults for pull_request_target-triggered workflows, directly citing this vulnerability class, changing default checkout behavior to reduce blast radius of future pwn-request findings.
Sources cited for JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn
- How JFrog's AI-Research Bot Found OSS CI/CD Vulnerabilities to Prevent Shai Hulud 3.0
- pull_request_target Exploitation - Part 1 - JFrog Security Research
- CVE-2026-24480 Detail - NVD
- QGIS: Critical validated RCE and Repository Takeover via GitHub Actions (GHSA-7h99-4f97-h6rw)
- CVE-2026-1699 Detail - NVD
- CVE-2026-1699: CWE-829 Inclusion of Functionality from Untrusted Control Sphere - Eclipse Theia Website
- Ansible.platform: RCE via unsafe pull_request_target (GHSA-fwqj-x86q-prmq)
- Telepresence: Unsafe pull_request_target allows Arbitrary Code Execution and Write Access via Makefile (GHSA-gc3r-m7gq-495f)
- Safer pull_request_target defaults for GitHub Actions checkout
- Securely using pull_request_target - GitHub Docs
- GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target
- RepoHunter - AI Security and CI/CD Security Research Tool by Barak Haryati
- pull_request_nightmare Part 1: Exploiting GitHub Actions for RCE and Supply Chain Attacks
Detection coverage for TL-2026-1535
As of 2026-03-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1535 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.