VDB

GCVE-110-CLOUD-2025-0121

GCVE-110-CLOUD-2025-0121
Advisory Published
Vulnetix · Advisory published March 26, 2025
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Affected Products

VendorProductVersionsPlatforms
GitHubCloud Services

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›