Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-commit.yml can be exploited by attackers, since untrusted code can be executed having full access to secrets (from the base repo). By exploiting the vulnerability is possible to exfiltrate GITHUB_TOKEN which has high privileges. GITHUB_TOKEN can be used to completely overtake the repo since the token has content write privileges. This vulnerability is fixed in commit 585c6a591440cd39f92374230ac5d65d7dd23d6a.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is an automated research snapshot of RSSNext/Folo, explicitly described in its README as a disposable lab for reproducing a public GitHub Actions workflow vulnerability; it is not a conventional exploit framework or a malware repository. The actionable vulnerable component is `.github/workflows/auto-fix-lint-format-commit.yml`: it uses `pull_request_target`, checks out the untrusted pull request head repository and branch, installs its dependencies, and runs its package scripts. That pattern permits a malicious contributor to execute code in the privileged base-repository workflow context. The repository has 100 files in the supplied archive and is principally a TypeScript/JavaScript monorepo for the Folo RSS reader, with Electron desktop code, Vite/Electron packaging configuration, Vercel cache-purge webhook code, and GitHub Actions CI/release workflows. No exploit launcher or hard-coded shell payload is present; exploitation is performed by supplying a crafted pull request.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.