CVE-2025-61584 affects serverless-dns, a RethinkDNS resolver deployable to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. In versions through and including 0.1.30, the pr.yml GitHub Actions workflow unsafely interpolates untrusted pull request data into a command executed on the GitHub Actions runner. Specifically, the workflow uses github.event.pull_request.head.repo.clone_url and github.head_ref as command input without safe handling. Because the workflow is triggered via pull_request_target, it executes with the target repository context and permissive default permissions, creating a high-risk condition where attacker-controlled PR metadata can influence runner command execution. The vulnerability enables an unauthorized attacker to abuse the CI workflow to push arbitrary data to the repository. If malicious code is introduced into the repository and later used by consumers, end users may execute attacker-controlled code when running serverless-dns.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 92-file JavaScript/TypeScript repository is an automated research snapshot of the upstream serverless-dns project, explicitly described in its README as a disposable lab for reproducing published GitHub Actions workflow vulnerabilities. The application itself is a legitimate serverless DNS resolver with DoH/DoT listeners, configurable blocklist filtering, DNS caching, optional GeoIP/log-push support, and Cloudflare Workers, Deno Deploy, Fastly, Fly.io, Node, and Bun deployment paths. Its main service entry points are `src/server-node.js`, `src/server-deno.ts`, `src/server-workers.js`, and `src/server-fastly.js`; DNS functionality is structured as modular resolver, cache, blocklist, user-configuration, command/control, and observability plugins. The security-relevant artifact is `.github/workflows/pr.yml`. It runs under `pull_request_target`, initially checks out the trusted base, installs dependencies, fetches and checks out `PR_HEAD_SHA`, then invokes ESLint on files selected from the untrusted PR diff. This mixes privileged PR-target execution with attacker-controlled checkout/configuration and is a known dangerous workflow design. The workflow also commits formatting changes and pushes them for same-repository PRs. No exploit script or destructive payload is committed; this is best classified as a PoC/reproduction environment for CI workflow compromise rather than an exploit targeting the DNS resolver itself. The resolver downloads blocklist and GeoIP data from RethinkDNS storage, forwards DNS via configurable DoH endpoints or plaintext DNS transport, and exposes Fly.io DoH/DoT service ports. Default development TLS material is present under `test/data/tls`; it is test-only material rather than evidence of a payload.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.