CVE-2025-54594 affects react-native-bottom-tabs in versions 0.9.2 and earlier. The repository's GitHub Actions workflow file github/workflows/release-canary.yml used the pull_request_target event in an unsafe way, causing untrusted code from forked pull requests to run in a privileged workflow context. An attacker could open a fork-based pull request that introduced a malicious preinstall script in package.json, then trigger the workflow by posting the !canary comment. When the workflow executed, the attacker-controlled code ran with access to repository secrets and elevated GitHub Actions privileges. This is a CI/CD pipeline vulnerability in which unsafe workflow design enabled arbitrary code execution within the repository automation environment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is an automated research snapshot of Callstack's React Native Bottom Tabs monorepo, explicitly described in README.md as a disposable lab for reproducing a published GitHub Actions workflow vulnerability. It is not a conventional standalone exploit and contains no malicious payload. The security-relevant file is `.github/workflows/release-canary.yml`: an `issue_comment` trigger accepts any PR comment containing `!canary`, checks out `refs/pull/<number>/head`, then installs dependencies, builds, versions, and publishes the PR-head code. The job grants `contents: write`, `id-token: write`, issue/PR write permissions, and supplies `NPM_TOKEN` and `GITHUB_TOKEN`. This is a privileged-context/PR-head execution pattern: attacker-controlled package scripts or build code may run during Yarn operations and access release credentials. The remaining repository consists of a Yarn/Turborepo TypeScript React Native bottom-tab library ecosystem, an Android/iOS/macOS/visionOS example app, documentation built with Rspress, and an Expo starter template. The example app includes only benign UI demonstrations; its remote-icon examples fetch SVGs from svgrepo.com and Wikimedia.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.