projen NodeProject-derived projects generated a GitHub Actions rebuild workflow that processed pull-request comments through the issue_comment event. Because this event runs with the target repository’s GITHUB_TOKEN rather than a fork-scoped token, an untrusted GitHub user could cause untrusted pull-request code to execute in the main repository context. In repositories without default-branch protection, this could enable modification of the main repository and access to repository-configured secrets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a 100-file TypeScript/JavaScript snapshot of projen v0.16.40, presented as a research artifact reproducing a historical GitHub Actions workflow vulnerability. It is not a conventional standalone exploit binary: the vulnerable/exploitable component is `.github/workflows/rebuild-bot.yml`. The repository otherwise contains project-generator configuration (`.projenrc.js`, package metadata, task definitions), a Node CLI launcher (`bin/projen` and `projen.bash`), documentation, licensing templates, and Jest-based TypeScript tests. The key workflow is triggered by an `issue_comment` event when a PR comment contains `@projen rebuild`. It queries the pull request URL, extracts `head.ref` and `head.repo.full_name`, checks out that PR head (including a fork), then executes `yarn install`, project synthesis, and a full build before committing and pushing. Because `issue_comment` workflows execute in the base repository context, this creates a privileged pull-request build pattern: untrusted fork code can run before the workflow pushes changes and while any context-authorized token/secrets are available. The supplied README states this is a disposable, historical reproduction and that included secrets/variables are generated dummy values. No CVE identifier or hard-coded exfiltration endpoint/payload is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.