Mesa (open-source Python agent-based modeling library) versions 3.5.0 and earlier contain a GitHub Actions workflow issue in benchmarks.yml where untrusted code can be checked out/executed in a privileged runner context. This unsafe workflow behavior can allow attacker-controlled code to run during CI, resulting in code execution on the privileged GitHub Actions runner. The issue was fixed in commit c35b8cd67fc89dd680ae218e49b77f6e1ee07a27.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is an automated research snapshot of the Mesa Python agent-based-modeling project, explicitly described in README.md as a disposable laboratory artifact for reproducing a published GitHub Actions workflow vulnerability. It is not a conventional standalone exploit tool and contains no hard-coded shell, reverse-shell, credential-theft, or destructive payload. Its exploitable capability is embodied in .github/workflows/benchmarks.yml: the workflow runs with pull_request_target and write permissions for issues and pull requests, initially checks out a baseline repository, then checks out the untrusted PR repository/ref and executes pip install --no-deps . followed by python benchmarks/global_benchmark.py. Both package installation/build hooks and the benchmark Python code can be modified in a malicious PR, yielding arbitrary code execution on the workflow runner. The workflow subsequently base64-encodes benchmark output and posts a PR comment through github-script. Repository contents otherwise consist primarily of Mesa library source under mesa/, benchmark utilities under benchmarks/, Sphinx documentation and Jupyter tutorials under docs/, and interactive Solara example models under mesa/examples/. The supplied README says the upstream Mesa project is not targeted and that the snapshot's variables/secrets are random dummy values.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.