VDB
GCVE-110-OSM-2025-1081
GCVE-110-OSM-2025-1081
Advisory PublishedCVSS 8.8/10
Repository contains an abusive GitHub Actions workflow that establishes unauthorized remote desktop access to a GitHub-hosted Windows runner. It changes operating-system security settings and a local account password before exposing RDP through a public tunneling service.
Malicious payload found in: .github/workflows/main.yml
The workflow runs on push or manual dispatch using windows-latest. It downloads the official ngrok Windows archive from https://bin.equinox.io/c/bNyj1mQVY4c/ngrok-v3-stable-windows-amd64.zip, extracts it, and authenticates using the NGROK_AUTH_TOKEN repository secret. It enables Terminal Services, enables the Remote Desktop firewall group, configures RDP network-level authentication, changes runneradmin to the hard-coded password P@ssw0rd!, and starts an ngrok TCP tunnel to local port 3389. The assigned public tunnel address is not statically available. The ngrok service is legitimate infrastructure abused by this workflow and is therefore not included as a verified malicious IOC.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | Default branch commit 4c6b6c9f4208de848ddea7844d4a414fbf96f692 (affected) | — |
References
Browse GCVE Records
386 records in the GCVE database · Updated September 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.