# JFrog RepoHunter Uncovers 13 CI/CD pull_request_target 'Pwn Request' Vulnerabilities Across Ansible, QGIS, Eclipse Theia, Typst, SDKMAN, Telepresence, Tencent, Ceph & More (CVE-2026-24480, CVE-2026-1699)

> JFrog's AI-driven security research tool RepoHunter (built by Barak Haryati) discovered 13 critical/high/medium CI/CD workflow vulnerabilities (10 Critical, 2 High, 1 Medium) across major open-source projects, all rooted in unsafe use of GitHub Actions' pull_request_target trigger combined with checkout of untrusted PR head code. Exploitation would let any external contributor achieve remote code execution in the base-repository CI context and exfiltrate GITHUB_TOKEN, npm/PyPI/Azure package-publishing tokens, and cross-repo deployment credentials -- the same 'pwn request' technique class behind the prior Shai-Hulud npm worm and the Nx/S1ngularity supply-chain incident. JFrog disclosed all findings responsibly with a ~3-month coordinated window; patches have shipped for the confirmed CVEs (QGIS, Eclipse Theia Website) and GHSA advisories (Ansible, SDKMAN, Telepresence, Typst, Tencent, Ceph, Parse-community, TC39, P4, Petgraph, Xorbitsai).

- **Published:** 2026-03-05T00:00:00Z
- **Last reviewed:** 2026-03-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1535
- **ID:** TL-2026-1535
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-24480, CVE-2026-1699

## Description

JFrog's Senior Director of Product Security, Barak Haryati, built RepoHunter, an AI-driven security research bot that automatically crawls open-source GitHub repositories, statically analyzes GitHub Actions workflow configurations, identifies patterns where untrusted external input (pull request branch names, file contents, commit messages, PR titles) reaches privileged execution contexts, and validates exploitability using AI-generated proof-of-concept scenarios. Over a multi-month campaign, RepoHunter surfaced 13 confirmed critical CI/CD takeover vulnerabilities in high-profile OSS projects: Ansible (ansible.platform, GHSA-fwqj-x86q-prmq), P4 Language (GHSA-6cw7-hxfh-8x94), Petgraph, QGIS (CVE-2026-24480 / GHSA-7h99-4f97-h6rw), SDKMAN (GHSA-cprm-c872-3fw7), tc39/proposal-amount (GHSA-43vf-c68r-43mr), Telepresence/CNCF (GHSA-gc3r-m7gq-495f), Typst (GHSA-j5gp-pf74-5pj6), Xorbitsai, Eclipse Theia Website (CVE-2026-1699), Tencent (GHSA-c44p-qr97-jccv), Ceph (GHSA-p433-fp4g-pc2c), and Parse-community (GHSA-6w8g-mgvv-3fcj).

The unifying root cause is the GitHub Actions 'pwn request' anti-pattern: a workflow triggers on pull_request_target (which runs in the base repository's security context, with full access to repository secrets and a GITHUB_TOKEN scoped to the base repo) but then explicitly checks out and executes the pull request's HEAD commit -- code fully controlled by the PR author, who may be an untrusted, first-time external contributor. This differs from the safer pull_request trigger, which runs in a sandboxed fork context with a read-only, minimally-scoped token.

Three distinct execution primitives were observed across the 13 findings: (1) test-based execution, where PR-supplied test files (Rust .rs files in Typst, npm test scripts in Theia) are executed directly by the CI test runner; (2) build-script execution, where PR-controlled build tooling (a modified gradlew wrapper in SDKMAN, npm install/build in Theia, Makefile targets in Telepresence, cargo in Petgraph) runs attacker-supplied commands during the normal build process; and (3) config/branch injection, where unsanitized metadata such as branch names or a malicious .pre-commit-config.yaml (QGIS) is interpolated into shell commands or hook definitions, yielding command injection.

A compounding factor documented across multiple advisories is actions/checkout's historical default of persist-credentials: true, which writes the ephemeral GITHUB_TOKEN into .git/config inside the runner workspace -- meaning any RCE primitive, however achieved, can trivially read the token back out of the git configuration file rather than needing to specifically target environment variables. GitHub subsequently changed the safer defaults for pull_request_target checkouts in its June 2026 Actions checkout update in direct response to this vulnerability class.

Per-project impact: Ansible's ansible.platform workflow exposed both a highly-privileged GITHUB_TOKEN (contents:write, actions:write, packages:write, pull-requests:write, deployments:write, attestations:write, pages:write) and a custom AAP_GATEWAY_REPO_TOKEN enabling lateral movement into other Ansible Automation Platform repositories, risking millions of downstream package downloads. QGIS's 'pre-commit checks' workflow allowed an attacker to add a malicious .pre-commit-config.yaml defining an arbitrary-execution hook, achieving RCE with a write-scoped GITHUB_TOKEN able to push commits, modify branches, and tamper with QGIS release artifacts consumed by governments, research institutions, and Linux distribution packagers. Eclipse Theia's Website repository preview.yml workflow exposed GITHUB_TOKEN plus DEPLOY_PREVIEW_TOKEN and NODE_AUTH_TOKEN, enabling secret exfiltration, malicious npm package publication under the eclipse-theia organization, and direct modification of the official Theia website. Typst's test_pr.yml exposed AZURE_PACKAGE_CREDENTIALS, GH_PRIVATE_KEY, GH_APP_ID, and GH_INSTALLATION_ID -- a GitHub App private key permitting on-demand minting of installation access tokens scoped across the entire Typst GitHub organization, the most severe blast radius among the 13 findings. SDKMAN's pull-requests.yml allowed a modified gradlew wrapper to execute with a contents:write GITHUB_TOKEN, permitting malicious commits/release tampering distributed to the JVM developer ecosystem. Telepresence's image-scan workflow (CNCF project) permitted RCE and write access via a crafted Makefile.

JFrog frames this disclosure explicitly against the 'Shai-Hulud' npm worm (August 2025) and its predecessor S1ngularity attack against the Nx build-system project, in which an unsanitized PR title reaching a pull_request_target workflow leaked roughly 83,000 secrets -- establishing that this exact technique class has already produced a real self-propagating supply-chain worm, elevating the credibility and urgency of these 13 preemptive findings. JFrog also contrasts its defensive RepoHunter research against a separate, unrelated malicious campaign it names 'hackerbot-claw,' which it says used similar AI-assisted reconnaissance techniques offensively to compromise repositories at Microsoft, DataDog, CNCF, and Trivy -- illustrating that the same automated-CI-recon capability is now being weaponized independently of JFrog's disclosure.

All 13 findings were disclosed under coordinated/responsible disclosure with roughly a three-month remediation window before JFrog's public blog post. Confirmed fixes: Ansible (PR #103, patched release 2.5.20260109), QGIS (commit 76a693cd91650f9b4e83edac525e5e4f90d954e9), Eclipse Theia Website (commit 2fb0cc4bfc372cfaef79feb4eebb6563778b2560). Remediation guidance from JFrog and GitHub: treat pull_request_target with extreme caution; never explicitly checkout PR head refs under that trigger; use pull_request instead wherever privileged actions are not required; apply least-privilege permissions blocks per workflow; sanitize all untrusted metadata (branch names, PR titles, file contents) before use in shell contexts; disable persist-credentials when the token is not needed post-checkout; and separate privileged automation (deploy, publish, release) into workflows that never execute untrusted code.

## MITRE ATT&CK

- T1593 Search Open Websites/Domains
- T1585 Establish Accounts
- T1199 Trusted Relationship
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1526 Cloud Service Discovery
- T1069 Permission Groups Discovery
- T1550 Use Alternate Authentication Material
- T1213 Data from Information Repositories
- T1119 Automated Collection
- T1102 Web Service
- T1567 Exfiltration Over Web Service
- T1565 Data Manipulation

## Sources

- [How JFrog's AI-Research Bot Found OSS CI/CD Vulnerabilities to Prevent Shai Hulud 3.0](https://jfrog.com/blog/jfrog-ai-bot-stopped-shai-hulud-3/)
- [pull_request_target Exploitation - Part 1 - JFrog Security Research](https://research.jfrog.com/post/part-1-pull-request-target-exploitation/)
- [CVE-2026-24480 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-24480)
- [QGIS: Critical validated RCE and Repository Takeover via GitHub Actions (GHSA-7h99-4f97-h6rw)](https://github.com/qgis/QGIS/security/advisories/GHSA-7h99-4f97-h6rw)
- [CVE-2026-1699 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-1699)
- [CVE-2026-1699: CWE-829 Inclusion of Functionality from Untrusted Control Sphere - Eclipse Theia Website](https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/332)
- [Ansible.platform: RCE via unsafe pull_request_target (GHSA-fwqj-x86q-prmq)](https://github.com/ansible/ansible.platform/security/advisories/GHSA-fwqj-x86q-prmq)
- [Telepresence: Unsafe pull_request_target allows Arbitrary Code Execution and Write Access via Makefile (GHSA-gc3r-m7gq-495f)](https://github.com/telepresenceio/telepresence/security/advisories/GHSA-gc3r-m7gq-495f)
- [Safer pull_request_target defaults for GitHub Actions checkout](https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/)
- [Securely using pull_request_target - GitHub Docs](https://docs.github.com/en/actions/reference/security/securely-using-pull_request_target)
- [GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target](https://cybersecuritynews.com/github-actions-checkout-update-workflow/)
- [RepoHunter - AI Security and CI/CD Security Research Tool by Barak Haryati](https://barak.haryati.io/repohunter)
- [pull_request_nightmare Part 1: Exploiting GitHub Actions for RCE and Supply Chain Attacks](https://orca.security/resources/blog/pull-request-nightmare-github-actions-rce/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1535
