A researcher disclosed a time-of-check-time-of-use (TOCTOU) flaw in Google Cloud Build’s GitHub pull-request comment-control workflow. An untrusted PR author could wait for a maintainer to approve execution with /gcbrun, quickly push a malicious commit, and have Cloud Build run that newer, unreviewed revision with the pipeline’s available secrets and IAM privileges. Google fixed the issue in June 2025 and awarded a $30,000 bug bounty.
The flaw is a form of Poisoned Pipeline Execution (PPE): attacker-controlled source changes cause a trusted CI/CD pipeline to execute malicious commands, enabling theft of CI credentials, lateral movement from build infrastructure, or delivery of trojanized artifacts. Google’s remediation binds builds to an adequately aged commit and requires an explicit full commit SHA when newer commits exist; organizations should also isolate unreviewed PR builds, protect CI configuration and trigger branches, require review before privileged pipeline execution, and limit repository and CI credential permissions.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Google marked the issue fixed by requiring a commit to be visible to Cloud Build for at least five seconds before it can be triggered by comment control. When a newer commit exists after the prior check, maintainers must provide the full commit SHA to trigger a run.
Google awarded the researcher a $30,000 bug bounty for the Cloud Build TOCTOU vulnerability.
Google acknowledged the reported Cloud Build comment-control race condition.
A researcher reported that Cloud Build's GitHub `/gcbrun` comment-control flow could execute a newer, unreviewed pull-request commit rather than the commit a maintainer intended to approve. The proof of concept replaced `cloudbuild.yaml` and caused Cloud Build to contact a Burp Collaborator domain; exploitation could expose build-accessible secrets or IAM privileges.
The researcher attempted a sub-second race using webhook timestamp granularity and an attempt to forge a past Git commit timestamp. Both bypass attempts failed, including because Cloud Build tied each run to a pending check.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.