VDB
GCVE-110-CLOUD-2025-0013
GCVE-110-CLOUD-2025-0013
Advisory Published
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code
in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply
chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be
downloaded and exploited within a 1-2 second window.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitHub | GitHub CodeQL, GitHub Actions | — | — |
Aliases
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.