Skip to content
GitHub Actions Checkout Adds Protection Against Malicious pull_request_target Workflows

GitHub Actions Checkout Adds Protection Against Malicious pull_request_target Workflows

Gbhackers • June 22, 2026

GitHub has implemented a major security enhancement in its Actions ecosystem with the release of actions/checkout v7, which aims to address a long-standing class of vulnerabilities known as “pwn requests.”

This update was announced on June 18, 2026, and introduces safer defaults for workflows triggered by the pull_request_target event. This event is one of the most frequently misused triggers in CI/CD pipelines and has been a common root cause of software supply chain compromises .

The pull_request_target event executes workflows in the context of the base repository, allowing access to sensitive resources such as the GITHUB_TOKEN, encrypted secrets, and caches associated with the default branch.

Although this design supports advanced automation scenarios, it also poses risks when workflows inadvertently check out and execute code from untrusted forked repositories.

Attackers can take advantage of this behavior by submitting malicious pull requests, allowing them to execute arbitrary code with elevated privileges, a technique commonly referred to as a “pwn request.”

To address this, GitHub’s actions /checkout v7 now blocks unsafe patterns by default when workflows attempt to fetch code from forked pull requests in pull_request_target or certain workflow_run contexts.

Specifically, the action will fail if it detects attempts to use untrusted inputs such as pull request head references, merge commits, or fork repository sources. This enforcement targets common insecure configurations like:

Such patterns previously enabled workflows to retrieve attacker-controlled code and execute it with full repository privileges. With v7, these configurations are now explicitly denied, reducing the attack surface across thousands of repositories that rely on GitHub Actions for automation.

GitHub confirmed that this protection will be backported to all supported major versions starting July 16, 2026. Repositories using floating version tags such as actions/checkout@v4 will automatically inherit the new safeguards.

However, workflows pinned to specific SHAs or minor versions must be manually updated, either through Dependabot or standard upgrade processes, to benefit from the protection.

Importantly, the update does not affect workflows triggered by the pull_request event, nor does it restrict same-repository pull requests. Additionally, GitHub acknowledges that this mitigation does not eliminate all forms of pwn request exploitation.

For instance, workflows that manually invoke git or GitHub CLI (gh) to fetch untrusted code within a run step remain vulnerable. Similarly, other event triggers such as issue_comment are not covered under this enforcement.

To preserve flexibility for legitimate use cases, such as generating reports or running authenticated checks on forked contributions—GitHub provides an explicit opt-out mechanism.

Developers can bypass the restriction by setting the allow-unsafe-pr-checkout flag in the checkout step, although this is strongly discouraged unless the workflow is carefully audited:

This change marks a critical step in hardening GitHub Actions against supply-chain threats, reinforcing secure-by-default principles while maintaining developer control.

Organizations leveraging CI/CD pipelines are advised to review their workflows, eliminate unsafe patterns, and adopt the updated version to reduce exposure to privilege escalation attacks originating from untrusted pull requests.

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

QNAP has issued security advisory QSA-26-10, which addresses 14 vulnerabilities affecting its widely used NAS…

Microsoft has announced a significant update to its Microsoft 365 ecosystem to enhance data protection.…

A malicious npm package, postcss-minify-selector-parser, has been discovered masquerading as a benign PostCSS utility and…

A suspicious file named “GST Debit Note Apr_26.com,” which triggered a deeper investigation and revealed…

Researchers have uncovered a systemic LLM credential exposure problem in the iOS ecosystem, with 282…

The LACUNA Chain's “Ghost Frames” technique introduces a new method for manipulating call stacks that…

Extracted Entities

Attack Types (1)

Companies (1)

Tools (1)