VDB

GCVE-110-CLOUD-2025-0040

GCVE-110-CLOUD-2025-0040
Advisory Published
Vulnetix · Advisory published March 26, 2025
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Affected Products

VendorProductVersionsPlatforms
GitHubCloud Services

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›