VDB
GCVE-110-CLOUD-2025-0067
GCVE-110-CLOUD-2025-0067
Advisory Published
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code
in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply
chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be
downloaded and exploited within a 1-2 second window.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitHub | Cloud Services | — | — |
References
Browse GCVE Records
67,506 records in the GCVE database · Updated August 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.