Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's GITHUB_TOKEN. Seeing as the artifact can be downloaded prior to the end of the workflow, there is a few seconds where an attacker can extract the token from the artifact and use it with the Github API to push malicious code or rewrite release commits in the AdeptLanguage/Adept repository. This issue has been patched in commit a1a41b7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is not a conventional standalone exploit repository. README.md identifies it as an automated, disposable research artifact for reproducing a published GitHub Actions workflow vulnerability, built from a verbatim snapshot of AdeptLanguage/Adept at commit 6a6455463213dabe52d49ceaaebd1f13cfee9018. The supplied source mainly implements the Adept general-purpose programming-language compiler in C11: lexical analysis (LEX), parsing (PARSE), AST construction/manipulation (AST), type inference (INFER), IR generation (IR/IRGEN), LLVM/C backends (BKEND), and compiler configuration/driver support (DRVR). CMake builds the adept executable and libadept, links LLVM, libcurl, zlib, and zstd, and invokes an external git clone for AdeptImport during configuration. The main security-relevant component is .github/workflows/remoteBuild.yml, a cross-platform Windows/macOS/Ubuntu CI and release workflow that installs build dependencies, builds and archives artifacts, and uses GitHub Actions—including a release-upload action authenticated with GITHUB_TOKEN. The visible workflow references are commit-pinned. No hard-coded victim host, IP address, reverse shell, destructive action, credential theft, or arbitrary command payload is present in the provided content. The stated research intent and workflow-based trigger support classifying it as a GitHub Actions proof-of-concept artifact, but the exact vulnerability mechanics cannot be verified because substantial workflow content is truncated and executable src/ implementation files are not included in the supplied listing.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.