securitylabs.datadoghq.com 38% of GitHub Actions Workflows Vulnerable to Script Injection
Article Content
- •38% of organizations face vulnerabilities in GitHub Actions workflows.
- •Misconfigured workflows can lead to credential leaks and compromised software.
- •Two out of three organizations have at least one vulnerability in their GitHub Actions.
Analysis shows that 38% of organizations using GitHub Actions workflows are exposed to script injection and unsafe trigger configurations. This vulnerability poses a significant risk in software supply chains, as GitHub Actions automate critical development tasks. The findings indicate that two out of three organizations have at least one vulnerability in their workflows or actions. Misconfigured workflows can serve as high-privilege entry points for attackers, allowing them to manipulate code, leak credentials, or compromise software. The report emphasizes the importance of securing workflows, especially given their role in managing credentials and automating deployments. The vulnerabilities stem from common practices like using third-party actions and broad permissions for the default GITHUB_TOKEN. Organizations are urged to assess their GitHub Actions configurations to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track DataDog in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…