nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable to Agentic Workflow Injection. The workflow sets allowed_non_write_users: ${{ github.event.issue.user.login }}, which means any logged-in GitHub user who opens an issue can reach this agentic workflow with attacker-controlled content. Untrusted issue title and body content are embedded directly into the prompt of anthropics/claude-code-action, and the workflow then runs a command-capable Claude agent with permission to comment on and relabel the current issue via gh. Because this workflow is triggered automatically on issues.opened, an external attacker can submit a crafted issue that steers the agent beyond its intended issue-triage purpose and influences authenticated issue actions. This vulnerability is fixed in 2.4.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This 100-file Python nnU-Net snapshot is explicitly presented as an automated research artifact for reproducing public GitHub Actions workflow vulnerabilities. Most files are nnU-Net documentation, medical-image dataset converters, competition-specific inference scripts, and batch/benchmark utilities. The security-relevant implementation is concentrated in `.github/workflows/` and `.github/agents/`: issue text and comments are injected into Claude Code prompts, while later workflows can be dispatched based on labels and execute with progressively stronger permissions. In particular, `bug-fix-pr.yml` checks out the repository and invokes an Opus agent with contents/issues/pull-requests write permissions and GitHub CLI/Git tools capable of branch creation, committing, pushing, PR creation, and issue-label updates. Its allowed `Bash(python:*)` tool also permits broad arbitrary Python execution in that privileged runner. The issue-triage workflow begins with read-only repository access plus issue-write access, while maintainer-triggered follow-up and complex-analysis jobs can dispatch the privileged remediation workflow after labels are applied. CI additionally downloads a public TotalSegmentator weight archive and PyTorch packages. No CVE, reverse shell, malware payload, external C2 host, or conventional application target is present; the intended target is the GitHub Actions/AI-agent trust boundary.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.