CVE-2024-47179 describes an Artifact Poisoning vulnerability in the RSSHub repository's GitHub Actions workflow (docker-test-cont.yml) prior to commit 64e00e7. The workflow would extract artifacts from a previous workflow run without validating their contents, allowing a malicious contributor to upload a crafted artifact containing files such as a malicious package.json. This could result in arbitrary code execution in the context of the privileged workflow, potentially leading to a full repository takeover. The vulnerability was fixed in commit 64e00e7 by validating artifact contents before extraction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is not a typical vulnerability exploit against RSSHub. It is a 100-file automated research artifact that snapshots DIYgod/RSSHub and modifies or preserves GitHub Actions workflows to reproduce a public CI/CD workflow vulnerability. The README explicitly identifies it as a disposable thesis lab, says the upstream project is not targeted, and states that all repository secrets/variables are dummy values. RSSHub itself is a Node.js TypeScript/JavaScript RSS-feed generator built around Hono; its server entry point is `lib/index.ts`, application middleware/routes are in `lib/`, an optional Vercel adapter is `api/vercel.ts`, and container deployment is provided by `Dockerfile` and `docker-compose.yml`. The material security-relevant workflow chain is: a pull request runs `docker-test.yml`, builds an image from PR-controlled repository content, exports it as `rsshub.tar.zst`, and uploads it as a GitHub Actions artifact. `docker-test-cont.yml` is triggered by the completed workflow via `workflow_run`; it downloads that artifact, runs `docker load`, and starts the resulting `rsshub:latest` container. This crosses a trust boundary because a downstream workflow executes an artifact built from untrusted PR input. The downstream job has pull-request write permission and uses authenticated GitHub Actions script/API steps, although the supplied workflow does not deliberately pass `GITHUB_TOKEN` or another secret into the container. Therefore, the repository demonstrates the unsafe artifact/image execution condition but contains no explicit post-exploitation command, reverse shell, token theft, or destructive behavior. Other notable code is ordinary RSSHub functionality: route discovery/registration (`lib/registry.ts`), RSS/Atom/JSON rendering, request filtering and sanitization, optional Redis caching, access-key checks, OpenAI-based title/description processing, optional remote configuration retrieval, anti-hotlink URL rewriting, and Sentry telemetry when configured. The included `routes-deprecated` JavaScript files fetch public content sources for RSS conversion and are unrelated to the CI workflow proof-of-concept. The `REMOTE_CONFIG` setting and configurable OpenAI endpoint are outbound-request features and should be treated carefully in any deployment, but they are not an embedded exploit payload. No CVE identifier is provided in the available content.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.