A critical misconfiguration in GitHub’s public actions/runner-images repository allowed pull requests from fork contributors to execute on persistent, non-ephemeral self-hosted runners between February and July 2023. A researcher bypassed contributor-status controls, achieved arbitrary code execution on azure-builds and macos-vmware infrastructure, and demonstrated persistence by leaving processes running after workflow jobs completed.
Persistent access could have exposed secrets used by legitimate runner-image builds, including a write-capable GITHUB_TOKEN, vCenter credentials, and Azure build-process credentials. An attacker could plausibly have altered GitHub-hosted runner-image build code, tampered with image-generation infrastructure, moved laterally into GitHub or Azure build engineering environments, or pivoted into GitHub’s macOS private cloud. GitHub triaged the disclosure in July 2023, applied repository mitigations, resolved it as a critical misconfiguration in November, and awarded the researcher a $20,000 bounty; organizations using public repositories with self-hosted runners should require approval for all external contributors and use isolated, ephemeral runners.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
GitHub resolved the report as a critical misconfiguration vulnerability and awarded the researcher a $20,000 HackerOne bug bounty.
The researcher removed the persistence mechanism from the affected self-hosted runner after maintaining access for five days.
GitHub acknowledged the report on July 24 and made initial repository mitigations on July 25. The researcher reported that GitHub's immediate fixes addressed the exposed runner configuration.
The researcher submitted the self-hosted runner misconfiguration vulnerability through HackerOne.
A minor typo-fix pull request from the researcher was merged, granting contributor status that bypassed the repository's default approval requirement for fork pull-request workflows.
GitHub's public actions/runner-images repository used non-ephemeral self-hosted runners for GitHub-hosted runner-image builds, with its exposed configuration spanning February through July 2023.
Praetorian researchers Adnan Khan and John Stawinski reported identifying thousands of potentially vulnerable public GitHub repositories using self-hosted runners and submitted more than 20 bug-bounty reports. Their research also assessed related risks affecting projects including PyTorch, Microsoft DeepSpeed, Cloudflare, blockchains, and TensorFlow, and expanded to Buildkite, Jenkins, and CircleCI.
Using contributor status and modified pull-request workflows, the researcher ran code on the azure-builds and macos-vmware runners, deployed persistence, and accessed build-job data including a write-capable GITHUB_TOKEN and clear-text macOS image-build secrets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceadnanthekhan.com
Open sourceadnanthekhan.com
Open sourcepraetorian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.