VDB

GCVE-110-CLOUD-2023-0003

GCVE-110-CLOUD-2023-0003
Advisory Published
Vulnetix · Advisory published December 20, 2023
A critical vulnerability in GitHub's actions/runner-images repository allowed arbitrary code execution on self-hosted runners, potentially enabling modification of GitHub's runner base images. The flaw stemmed from misconfigured self-hosted runners on a public repository with default workflow approval settings. The researcher gained persistence, accessed secrets, and could have inserted malicious code into GitHub's runner images used by customers.

Affected Products

VendorProductVersionsPlatforms
GitHubGitHub Actions
GitHubCloud Services

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›