VDB

GCVE-110-CLOUD-2025-0013

GCVE-110-CLOUD-2025-0013
Advisory Published
Vulnetix · Advisory published March 26, 2025
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Affected Products

VendorProductVersionsPlatforms
GitHubGitHub CodeQL, GitHub Actions

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›